This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below. CVE-2026-73445 has been fixed in the following releases: - 4.36.1F and later releases in the 4.36.x train - 4.35.6M and later releases in the 4.35.x train - 4.34.8M and later releases in the 4.34.x train - 4.33.9M and later releases in the 4.33.x train No hotfix is available for this issue.
Workaround
1. Include exactly one UploadRequest in a gNSI Authz Rotate request. 2. Use a gNSI Authz policy that restricts gNSI Authz use to only those who strictly need it. Below is an example policy that only allows user "Neo" to rotate Authz policies: { "name":"restrict-authz-policy", "allow_rules":[ { "name":"neoallow", "request":{ "paths":[ "/gnsi.authz.v1.Authz/Rotate" ], "headers":[ { "key":"username", "values":[ "Neo" ] } ] } }, { "name":"allow-gnmi", "request":{ "paths":[ "/gnmi.gNMI/*" ] } }, { "name":"allow-gnoi", "request":{ "paths":[ "/gnoi.*" ] } } ] } Ideally, this policy would be uploaded via a gNSI client for correct version and created-on metadata handling. However, the policy can also be written directly to the active policy file: switch#bash timeout 100 echo "{\"name\":\"restrict-authz-policy\",\"allow_rules\":[{\"name\":\"neoallow\",\"request\":{\"paths\":[\"\/gnsi.authz.v1.Authz\/Rotate\"],\"headers\":[{\"key\":\"username\",\"values\":[\"Neo\"]}]}},{\"name\":\"allow-gnmi\",\"request\":{\"paths\":[\"\/gnmi.gNMI\/*\"]}},{\"name\":\"allow-gnoi\",\"request\":{\"paths\":[\"\/gnoi.*\"]}}]}" | sudo tee /persist/sys/gnsi/authz/policy.json && sleep 11
Wed, 16 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Sep 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | On affected platforms running Arista EOS, an issue with the gRPC Network Security Interface (gNSI) Authz Rotate RPC may cause an incorrect Authz policy which was uploaded in the ongoing RPC stream to become active. This does not affect Bootz. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks. | |
| Title | Security Advisory 0167 | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-09-16T17:35:56.813Z
Reserved: 2026-08-12T16:42:47.920Z
Link: CVE-2026-73445
Updated: 2026-09-16T17:35:53.784Z
Status : Awaiting Analysis
Published: 2026-09-16T09:17:04.853
Modified: 2026-09-16T19:09:28.447
Link: CVE-2026-73445
No data.
OpenCVE Enrichment
Updated: 2026-09-16T14:00:11Z