Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5477 articles · 220951 vulns · 37/41 feeds (7d)
← Back to list
10.0
CVE-2026-73453PATCHED
arista · eos

Security Advisory 0174

Description

An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code execution under certain conditions on affected platforms running Arista EOS configured with P4Runtime. P4Runtime is disabled by default in Arista EOS. By crafting a malicious packet during the initiation of a P4Runtime session, an attacker can obtain complete administrative control over the compromised switch. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.

Affected Products

VendorProductVersions
aristaeos4.36.0F, 4.35.0F, 4.34.0F, 4.33.0F, 4.32.0F, 4.31.0F, 4.30.0F, 4.29.2F

References

  • https://www.arista.com/en/support/advisories-notices/security-advisory/24730-security-advisory-0174(vendor-advisory)

Related News (1 articles)

Tier C
VulDB6d ago
CVE-2026-73453 | Arista EOS up to 4.36.1F P4Runtime code injection
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.110.0 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
4.34.0F4.33.0F4.32.0F4.31.0F4.30.0F
CWECWE-94
PublishedSep 16, 2026
Trending Score22
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-93952EXPKEV
Security Advisory 0183
Trending: 130
HIGHCVE-2026-73458
On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various rou
Trending: 24
CRITICALCVE-2026-73456
Under certain circumstances, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch.
Trending: 23
MEDIUMCVE-2026-19641
On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources, resulting in legit
Trending: 22
HIGHCVE-2026-73464
Security Advisory 0166
Trending: 21

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 16, 2026
Discovered by ZDM
Sep 16, 2026
Patch Available
Sep 17, 2026