Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-73447: Arista EOS Certz/Bootz allows attacker to run commands as root

CVE-2026-73447 · published 1 day ago
Summary

Arista EOS devices that use the gNSI Certz or Bootz services can be tricked into executing any command with full system rights. An attacker who can send a specially crafted request can gain administrator control of the device. Apply the latest Arista EOS security update and limit access to these services to trusted networks.

What to do
  • Update arista networks eos to version 4.31.0F or later.
Affected software
VendorProductAffected versions
arista networks eos < 4.31.0F
Original advisory text
Security Advisory 0162 - gNSI Certz/Bootz OS Command Injection via Crafted Rotate Request
A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full device compromise. An authenticated user can exploit gRPC Network Security Interface (gNSI) Certz service on Arista EOS-based products to escalate privileges and execute arbitrary OS commands via a crafted Certz Rotate request. The Bootz service is also affected.
Severity
9.4 Critical
CVSS 3.1: 9.1 (NVD)
CVSS 4.0: 9.4 (NVD)
Type
CWE-78OS Command Injection
Timeline
Published16 Sep 2026
Updated17 Sep 2026
First seen16 Sep 2026
Sources
CVE-2026-73447 · MITRE
Track software like this
Free during beta