GPU VulnDB

Database/Firmware, BMC & network fabric

Arista EOS P4Runtime: unauthenticated client can gain full administrative control of the switch

CVSS 9.5CVE-2026-73453Firmware, BMC & network fabriccurated

Impact

An attacker who can open a P4Runtime session to the switch can run arbitrary code and take complete administrative control of it. On a GPU fleet, the leaf and spine switches carrying the east-west training fabric and the storage network sit between every tenant; an attacker who owns one can mirror or redirect traffic across tenant boundaries, break up collectives, or use the switch as a foothold on the management network. No authentication is required, and the flaw is reached during session initiation, so nothing in the normal authorization path gets a chance to stop it. Arista rates it 9.5 and states P4Runtime is disabled by default, which limits exposure to fleets that deliberately turned it on.

Who can reach it

Anyone with network reach to the P4Runtime gRPC endpoint on an affected switch. No authentication needed. Only switches explicitly configured with P4Runtime are affected; it is off by default in EOS.

What to do

If P4Runtime is not in use, confirm it is disabled - that removes the exposure entirely. If it is in use, consult Arista security advisory 0174 for the fixed EOS releases and hotfix availability and plan a per-switch upgrade window; a control-plane fabric switch cannot normally be upgraded without draining traffic off it or relying on redundant paths. The record does not name a fixed version, so take it from the advisory.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.