Database/Firmware, BMC & network fabric

Arista EOS P4Runtime: unauthenticated client can gain full administrative control of the switch
Impact
An attacker who can open a P4Runtime session to the switch can run arbitrary code and take complete administrative control of it. On a GPU fleet, the leaf and spine switches carrying the east-west training fabric and the storage network sit between every tenant; an attacker who owns one can mirror or redirect traffic across tenant boundaries, break up collectives, or use the switch as a foothold on the management network. No authentication is required, and the flaw is reached during session initiation, so nothing in the normal authorization path gets a chance to stop it. Arista rates it 9.5 and states P4Runtime is disabled by default, which limits exposure to fleets that deliberately turned it on.
Who can reach it
Anyone with network reach to the P4Runtime gRPC endpoint on an affected switch. No authentication needed. Only switches explicitly configured with P4Runtime are affected; it is off by default in EOS.
What to do
If P4Runtime is not in use, confirm it is disabled - that removes the exposure entirely. If it is in use, consult Arista security advisory 0174 for the fixed EOS releases and hotfix availability and plan a per-switch upgrade window; a control-plane fabric switch cannot normally be upgraded without draining traffic off it or relying on redundant paths. The record does not name a fixed version, so take it from the advisory.
References
Related entries
- Arista EOS gNSI Certz: crafted Rotate request runs arbitrary OS commands as rootCVE-2026-73447 · Arista EOS (gNSI Certz service, also Bootz)Critical
- Arista EOS: gRPC OpenConfig requests authorized at the wrong privilege levelCVE-2026-73461 · Arista EOS (AAA authorization for gRPC/OpenConfig)Critical
- Arista EOS (redundant supervisor, RPR/SSO): On modular chassis with dual supervisors running RPR or SSO redundancyCVE-2023-24509 · Arista EOS (redundant supervisor, RPR/SSO)Critical
- Software House iSTAR Ultra firmware verification and web application (tested through 6.9.2): The controller verifiesCVE-2025-53696 · Software House iSTAR Ultra firmware verification and web application (tested through 6.9.2)Critical
- Phala dcap-qvl - the Rust/npm/Python DCAP quote verification library used to verify Intel SGX and TDX attestationCVE-2026-22696 · Phala dcap-qvl - the Rust/npm/Python DCAP quote verification library used to verify Intel SGX and TDX attestation…Critical
- Voltronic Power SNMP Web Pro: unauthenticated firmware upload yields root on the UPS management cardCVE-2026-44402 · Voltronic Power SNMP Web Pro 1.1 (upload.cgi firmware update endpoint)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.