GPU VulnDB

Database/Firmware, BMC & network fabric

Arista EOS gNSI Certz: crafted Rotate request runs arbitrary OS commands as root

CVSS 9.4CVE-2026-73447Firmware, BMC & network fabriccurated

Impact

An already-authenticated user of the gNSI Certz service can escalate to root command execution and fully compromise the switch. Certz is the certificate rotation interface, so the accounts that reach it are automation identities held by provisioning and PKI tooling - credentials that tend to be shared fleet-wide rather than per-switch. One compromised automation credential therefore converts into root on every switch that trusts it, including the fabric switches between tenants. The Bootz provisioning service is affected by the same issue.

Who can reach it

An authenticated client with access to the gNSI Certz (or Bootz) service, reachable over the network on the management plane. Requires high privileges per the vendor's vector, but that is the level automation accounts normally hold.

What to do

Restrict gNSI Certz and Bootz reachability to the provisioning hosts that need it and audit which identities hold that access. Apply the fixed EOS release or hotfix listed in Arista security advisory 0162 on a per-switch maintenance window; the record does not name a fixed version.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.