Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.5

CVE-2026-73453: Arista EOS switches can be taken over via P4Runtime

CVE-2026-73453 · published 11 days ago
Summary

If the P4Runtime feature is turned on in Arista EOS, an attacker who can send a specially crafted packet can gain full administrative control of the switch. The attack does not require any credentials and works only when P4Runtime is enabled. Disable P4Runtime if you do not need it and apply any updates from Arista that address this risk.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
arista networks eos <= 4.36.1F
Original advisory text
Security Advisory 0174
An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code execution under certain conditions on affected platforms running Arista EOS configured with P4Runtime. P4Runtime is disabled by default in Arista EOS. By crafting a malicious packet during the initiation of a P4Runtime session, an attacker can obtain complete administrative control over the compromised switch.

This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
Severity
9.5 Critical
CVSS 3.1: 10.0 (NVD)
CVSS 4.0: 9.5 (NVD)
Exploitation
EPSS <1%
Type
CWE-94Code Injection
Timeline
Published16 Sep 2026
Updated27 Sep 2026
First seen16 Sep 2026
Sources
CVE-2026-73453 · MITRE
Track software like this
Free during beta