PT-2026-92042 · Arista · Eos

CVE-2026-73456

·

Published

2026-09-15

·

Updated

2026-09-22

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Arista EOS (affected versions not specified)
Description On platforms running Arista EOS with the gRPC Network Packet Sampling Interface (gNPSI) enabled, an unauthenticated gNPSI client can send a specially crafted request. This can lead to arbitrary code execution, allowing an attacker to gain full administrative control over the affected switch.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73456

Affected Products

Eos