Security Advisory 0169
Summary
| CVE | CVE-2026-73463 |
|---|---|
| State | PUBLISHED |
| Assigner | Arista |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-16 09:17:05 UTC |
| Updated | 2026-09-16 19:08:50 UTC |
| Description | On affected platforms running Arista EOS, when multiple gRPC Network Security Interface (gNSI) transports are configured, a race condition in the gNSI Authz service may cause a policy rotation to fail silently. An authenticated user whose access was revoked by the new policy may retain unauthorized access to gRPC interfaces. This does not affect Bootz. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks. |
Risk And Classification
Primary CVSS: v4.0 6 MEDIUM from [email protected]
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.001990000 probability, percentile 0.099330000 (date 2026-09-16)
Problem Types: CWE-362 | CWE-362 CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 6 | MEDIUM | CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 6 | MEDIUM | CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
| 3.1 | [email protected] | Secondary | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N |
| 3.1 | CNA | CVSS | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N |
CVSS v4.0 Breakdown
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Arista Networks | EOS | affected 4.36.0F 4.36.0.1F custom | 710 Series, 720D Series, 720XP/722XPM Series, 750X Series, 7010TX Series, 7020R/R4 Series, 7130 Series running EOS, 7170 Series, 7050X3/X4 Series, 7060X/X2/X4/X5/X6 Series, 7260X/X3 Series, 7280R/R2/R3/R4 Series, 7300X/X3 Series, 7320X Series, 7358X4 Series, 7368X4 Series, 7388X5 Series, 7500R/R2/R3 Series, 7800R3/R4 Series, 7700R4 Series, AWE 5000 Series, AWE 7200R Series, CloudEOS, cEOS-lab, vEOS-lab, CloudVision eXchange, virtual or physical appliance |
| CNA | Arista Networks | EOS | affected 4.35.0F 4.35.5M custom | 710 Series, 720D Series, 720XP/722XPM Series, 750X Series, 7010TX Series, 7020R/R4 Series, 7130 Series running EOS, 7170 Series, 7050X3/X4 Series, 7060X/X2/X4/X5/X6 Series, 7260X/X3 Series, 7280R/R2/R3/R4 Series, 7300X/X3 Series, 7320X Series, 7358X4 Series, 7368X4 Series, 7388X5 Series, 7500R/R2/R3 Series, 7800R3/R4 Series, 7700R4 Series, AWE 5000 Series, AWE 7200R Series, CloudEOS, cEOS-lab, vEOS-lab, CloudVision eXchange, virtual or physical appliance |
| CNA | Arista Networks | EOS | affected 4.34.0F 4.34.7M custom | 710 Series, 720D Series, 720XP/722XPM Series, 750X Series, 7010TX Series, 7020R/R4 Series, 7130 Series running EOS, 7170 Series, 7050X3/X4 Series, 7060X/X2/X4/X5/X6 Series, 7260X/X3 Series, 7280R/R2/R3/R4 Series, 7300X/X3 Series, 7320X Series, 7358X4 Series, 7368X4 Series, 7388X5 Series, 7500R/R2/R3 Series, 7800R3/R4 Series, 7700R4 Series, AWE 5000 Series, AWE 7200R Series, CloudEOS, cEOS-lab, vEOS-lab, CloudVision eXchange, virtual or physical appliance |
| CNA | Arista Networks | EOS | affected 4.33.0F 4.33.8M custom | 710 Series, 720D Series, 720XP/722XPM Series, 750X Series, 7010TX Series, 7020R/R4 Series, 7130 Series running EOS, 7170 Series, 7050X3/X4 Series, 7060X/X2/X4/X5/X6 Series, 7260X/X3 Series, 7280R/R2/R3/R4 Series, 7300X/X3 Series, 7320X Series, 7358X4 Series, 7368X4 Series, 7388X5 Series, 7500R/R2/R3 Series, 7800R3/R4 Series, 7700R4 Series, AWE 5000 Series, AWE 7200R Series, CloudEOS, cEOS-lab, vEOS-lab, CloudVision eXchange, virtual or physical appliance |
| CNA | Arista Networks | EOS | affected 4.32.0F 4.32.11M custom | 710 Series, 720D Series, 720XP/722XPM Series, 750X Series, 7010TX Series, 7020R/R4 Series, 7130 Series running EOS, 7170 Series, 7050X3/X4 Series, 7060X/X2/X4/X5/X6 Series, 7260X/X3 Series, 7280R/R2/R3/R4 Series, 7300X/X3 Series, 7320X Series, 7358X4 Series, 7368X4 Series, 7388X5 Series, 7500R/R2/R3 Series, 7800R3/R4 Series, 7700R4 Series, AWE 5000 Series, AWE 7200R Series, CloudEOS, cEOS-lab, vEOS-lab, CloudVision eXchange, virtual or physical appliance |
| CNA | Arista Networks | EOS | affected 4.31.0F 4.31.10M custom | 710 Series, 720D Series, 720XP/722XPM Series, 750X Series, 7010TX Series, 7020R/R4 Series, 7130 Series running EOS, 7170 Series, 7050X3/X4 Series, 7060X/X2/X4/X5/X6 Series, 7260X/X3 Series, 7280R/R2/R3/R4 Series, 7300X/X3 Series, 7320X Series, 7358X4 Series, 7368X4 Series, 7388X5 Series, 7500R/R2/R3 Series, 7800R3/R4 Series, 7700R4 Series, AWE 5000 Series, AWE 7200R Series, CloudEOS, cEOS-lab, vEOS-lab, CloudVision eXchange, virtual or physical appliance |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.arista.com/en/support/advisories-notices/security-advisory/24725-securit... | [email protected] | www.arista.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Additional Advisory Data
Solutions
CNA: The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below. CVE-2026-73463 has been fixed in the following releases: - 4.36.1F and later releases in the 4.36.x train - 4.35.6M and later releases in the 4.35.x train - 4.34.7.1M and later releases in the 4.34.x train - 4.33.9M and later releases in the 4.33.x train No hotfix is available for this issue.
Workarounds
CNA: Restrict the set of users that can enable gNSI on OpenConfig / Octa transports via the CLI. Firstly, configure AAA authorization. The following is an example of configuring AAA authorization for all privilege levels using only the local user database: switch(config)#aaa authorization commands all default local switch(config)#aaa authorization config-commands Now restrict a sufficient subset of all roles from enabling gNSI services. In the below example, we prohibit just network-operators: switch(config-mgmt-api-gnsi)#role network-operator switch(config-role-network-operator)#10 deny mode mgmt-api-gnsi command transport gnmi .* 256 permit command .*