gRPC Network Security Interface Vulnerability in Arista EOS
CVE-2026-73445
6.9MEDIUM
What is CVE-2026-73445?
An issue has been identified in the gRPC Network Security Interface (gNSI) on Arista EOS platforms, potentially allowing an uploaded Authz policy to become unintentionally active in the ongoing RPC stream. This vulnerability does not affect the Bootz feature. Discovered internally by Arista, there are currently no reported cases of exploitation within customer environments. Organizations utilizing Arista EOS should monitor this vulnerability for any related updates to maintain network security.
Affected Version(s)
EOS 4.36.0F <= 4.36.0.1F
EOS 4.35.0F <= 4.35.5M
EOS 4.34.0F <= 4.34.7M
