Metrics
Affected Vendors & Products
No advisories yet.
Solution
The following EOS releases contain the fix for this vulnerability: - 4.33.9M and later releases in the 4.33.x train - 4.34.7.1M and later releases in the 4.34.x train - 4.35.6M and later releases in the 4.35.x train - 4.36.1F and later releases in the 4.36.x train No hotfix is available for this vulnerability.
Workaround
Disable gNSI Credentialz service. Note: Disabling Credentialz prevents gNSI-based credential rotation (SSH keys, passwords, host parameters) but does not affect traditional EOS CLI credential management. Credentialz is not enabled by default. switch(config)#management api gnsi switch(config-mgmt-api-gnsi)#no service credentialz
Wed, 16 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Sep 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | On affected platforms running Arista EOS with gRPC Network Security Interface (gNSI) Credentialz configured, a specially crafted request can cause unintended modifications to the target account's properties. This may result in the account being assigned elevated privileges or access beyond what an administrator intended. | |
| Title | Security Advisory 0165 | |
| Weaknesses | CWE-77 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-09-16T14:51:32.310Z
Reserved: 2026-08-12T16:42:47.921Z
Link: CVE-2026-73454
Updated: 2026-09-16T14:51:24.778Z
Status : Received
Published: 2026-09-16T09:17:05.020
Modified: 2026-09-16T15:17:42.803
Link: CVE-2026-73454
No data.
OpenCVE Enrichment
Updated: 2026-09-16T15:00:07Z