Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5403 articles · 221035 vulns · 37/41 feeds (7d)
← Back to list
8.8
CVE-2026-73464PATCHED
arista · eos

Security Advisory 0166

Description

On affected platforms running Arista EOS with gRPC Network Management Interface (gNMI) enabled, a specially crafted request could allow a malicious authenticated client with gRPC Network Management Interface (gNMI) access to execute arbitrary code with root privileges on the switch.

Affected Products

VendorProductVersions
aristaeos4.29.0F, 4.30.0F, 4.31.0F, 4.32.0F, 4.33.0F, 4.34.0F, 4.35.0F, 4.36.0F

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
aristaeoscert_advisory90%

References

  • https://www.arista.com/en/support/advisories-notices/security-advisory/24722-security-advisory-0166(vendor-advisory)

Related News (2 articles)

Tier B
BSI Advisories6d ago
[NEU] [hoch] Arista EOS: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB6d ago
CVE-2026-73464 | Arista EOS up to 4.36.0.1F gRPC Network Management Interface code injection
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.18.8 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
4.30.0F4.31.0F4.32.0F4.33.0F
CWECWE-94
PublishedSep 16, 2026
Last enriched6d ago
Trending Score21
Source articles2
Independent2
Info Completeness5/14
Missing: vendor, product, versions, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-93952EXPKEV
Security Advisory 0183
Trending: 129
HIGHCVE-2026-73458
On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various rou
Trending: 24
CRITICALCVE-2026-73456
Under certain circumstances, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch.
Trending: 23
CRITICALCVE-2026-73453
Security Advisory 0174
Trending: 22
MEDIUMCVE-2026-19641
On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources, resulting in legit
Trending: 22

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 16, 2026
Discovered by ZDM
Sep 16, 2026
Patch Available
Sep 17, 2026