Description
On affected platforms running Arista EOS with gRPC Network Security Interface (gNSI) Credentialz configured, a specially crafted request can cause unintended modifications to the target account's properties. This may result in the account being assigned elevated privileges or access beyond what an administrator intended.
Published: 2026-09-16
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Account Privilege Escalation
Action: Patch Immediately
AI Analysis

Impact

The vulnerability resides in the gNSI Credentialz service of Arista EOS. A crafted request can alter a target account's properties, granting it elevated privileges or unintended access. This may compromise confidentiality, integrity, and availability of the system, enabling attackers to perform further malicious actions.

Affected Systems

The affected product is Arista Networks EOS. Versions impacted include all releases in the 4.33.x train prior to 4.33.9M, the 4.34.x train prior to 4.34.7.1M, the 4.35.x train prior to 4.35.6M, and the 4.36.x train prior to 4.36.1F, as identified by the vendor.

Risk and Exploitability

The CVSS score of 8.6 reflects high severity. The EPSS score is below 1%, indicating a very low probability of exploitation in the wild, and the vulnerability is not currently listed in CISA KEV. Based on the description, the likely attack vector involves an attacker delivering a malicious gNSI request over the management network; the exploit requires the gNSI Credentialz service to be enabled.

Generated by OpenCVE AI on September 16, 2026 at 14:55 UTC.

Remediation

Vendor Solution

The following EOS releases contain the fix for this vulnerability: - 4.33.9M and later releases in the 4.33.x train - 4.34.7.1M and later releases in the 4.34.x train - 4.35.6M and later releases in the 4.35.x train - 4.36.1F and later releases in the 4.36.x train No hotfix is available for this vulnerability.


Vendor Workaround

Disable gNSI Credentialz service. Note: Disabling Credentialz prevents gNSI-based credential rotation (SSH keys, passwords, host parameters) but does not affect traditional EOS CLI credential management. Credentialz is not enabled by default. switch(config)#management api gnsi switch(config-mgmt-api-gnsi)#no service credentialz


OpenCVE Recommended Actions

  • Upgrade EOS to the latest firmware version within the 4.33.x, 4.34.x, 4.35.x, or 4.36.x train that includes the fix (e.g., 4.33.9M or newer, 4.34.7.1M or newer, 4.35.6M or newer, or 4.36.1F or newer).
  • If an upgrade cannot be performed promptly, disable the vulnerable service by configuring 'switch(config-mgmt-api-gnsi)#no service credentialz'.
  • Restrict access to the gNSI API to trusted management hosts, and implement network segmentation or firewall rules to limit traffic to the management interface.
  • Disable or remove any unused management protocols that expose the gNSI interface to reduce attack surface.

Generated by OpenCVE AI on September 16, 2026 at 14:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description On affected platforms running Arista EOS with gRPC Network Security Interface (gNSI) Credentialz configured, a specially crafted request can cause unintended modifications to the target account's properties. This may result in the account being assigned elevated privileges or access beyond what an administrator intended.
Title Security Advisory 0165
Weaknesses CWE-77
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-17T03:56:53.682Z

Reserved: 2026-08-12T16:42:47.921Z

Link: CVE-2026-73454

cve-icon Vulnrichment

Updated: 2026-09-16T14:51:24.778Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T09:17:05.020

Modified: 2026-09-17T04:18:00.073

Link: CVE-2026-73454

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T15:00:07Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')