Account Property Modification Vulnerability in Arista EOS by Arista Networks
CVE-2026-73454

8.6HIGH

Key Information:

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-73454?

A vulnerability has been identified in Arista EOS that affects systems configured with gRPC Network Security Interface (gNSI) Credentialz. A specially crafted request can inadvertently modify attributes of the target account, potentially granting elevated privileges or access that was not initially intended by the administrator. This risk emphasizes the importance of stringent security practices and the timely application of patches to safeguard sensitive information and access levels.

Affected Version(s)

EOS 710 Series 4.30.0F < 4.31.0F

EOS 710 Series 4.31.0F < 4.32.0F

EOS 710 Series 4.32.0F < 4.33.0F

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.