Impact
An ARISTA device running EOS can be compromised by an attacker Network Security Interface. By sending aNSI Certz service or the Bootz service, the attacker can inject OS commands that are executed with root privileges. This command injection flaw is a classic input validation weakness (CWE‑78) and results in full device compromise, giving the attacker total control over the system.
Affected Systems
Arista Networks EOS devices are affected. The vulnerability is fixed in EOS releases 4.33.9M and later in the 4.33.x train, 4.34.7.1M and later in the 4.34.x train, 4.35.6M and later in the 4.35.x train, and 4.36.1F and later in the 4.36.x train. Devices running earlier releases are susceptible.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity, while the EPSS score of less than 1% shows the likelihood of exploitation is currently low but not zero. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated privileged user to target the gNSI Certz or Bootz service, and the attack vector is inferred to be over the device’s internal gRPC interface following these privileges.
OpenCVE Enrichment