Privilege Escalation in Arista EOS Products
CVE-2026-73447
9.4CRITICAL
What is CVE-2026-73447?
A privileged attacker can exploit a specific operation involving the gRPC Network Security Interface (gNSI) on Arista EOS-based products. This exploitation allows an authenticated user to escalate privileges and execute arbitrary OS commands through a specially crafted Certz Rotate request. Additionally, the Bootz service is also susceptible to this vulnerability, which poses a significant risk of full device compromise.
Affected Version(s)
EOS 710 Series 4.30.2F < 4.31.0F
EOS 710 Series 4.31.0F < 4.32.0F
EOS 710 Series 4.32.0F < 4.33.0F
