GPU VulnDB

Database/Firmware, BMC & network fabric

Arista EOS gNMI: crafted request from an authenticated client executes code as root

CVSS 8.7CVE-2026-73464Firmware, BMC & network fabriccurated

Impact

An authenticated client with gNMI access can send a crafted request and execute arbitrary code with root privileges on the switch. gNMI is the standard streaming telemetry and configuration interface, so it is enabled on essentially every switch in an automated fabric and its credentials are held by monitoring and config-management systems. Compromise of any one of those systems therefore becomes root on the fabric switches that sit between tenants, with no further escalation step. Arista's vector rates the required privileges as low.

Who can reach it

An authenticated client with gNMI access over the network - in practice the telemetry collector or config-management identity. Applies to switches with gNMI enabled.

What to do

Limit gNMI reachability to the collectors and automation hosts that require it, and rotate the credentials those hosts hold if you suspect exposure. Apply the fixed EOS release or hotfix from Arista security advisory 0166 per switch; the record does not name a fixed version.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.