GPU VulnDB

Database/Firmware, BMC & network fabric

Arista EOS gNPSI: unauthenticated request yields arbitrary code execution on the switch

CVSS 9.2CVE-2026-73456Firmware, BMC & network fabriccurated

Impact

A crafted gNPSI request from an unauthenticated client gives arbitrary code execution and full administrative control of the switch. gNPSI is a telemetry streaming interface, so it is typically enabled on exactly the switches an operator instruments most heavily - the fabric carrying training traffic. Control of a leaf or spine lets an attacker observe or divert traffic that crosses tenant boundaries and pivot into the management network. Only switches with gNPSI enabled are affected.

Who can reach it

Anyone who can reach the gNPSI endpoint on an affected switch, typically from the management or telemetry VLAN. No authentication required.

What to do

Disable gNPSI where it is not consumed, and restrict reachability of the telemetry endpoint to the collectors that need it. For switches that must keep it, take the fixed EOS release or hotfix from Arista security advisory 0158 and schedule a per-switch upgrade; the record does not name a fixed version.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.