Arista EOS Vulnerability Allows Arbitrary Code Execution via P4Runtime
CVE-2026-73453

9.5CRITICAL

Key Information:

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-73453?

A vulnerability exists in Arista EOS where an unauthenticated P4Runtime client may execute arbitrary code on affected platforms. Although P4Runtime is disabled by default, an attacker can exploit this flaw by sending a specially crafted packet during the initiation of a P4Runtime session, leading to complete administrative control over the compromised switch. Arista's internal discovery of this issue indicates a lack of known malicious exploitation in customer environments.

Affected Version(s)

EOS 710 Series 4.36.0F <= 4.36.1F

EOS 710 Series 4.35.0F <= 4.35.5M

EOS 710 Series 4.34.0F <= 4.34.7M

References

CVSS V4

Score:
9.5
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.