CVE-2026-73439
- EPSS 0.33%
- Veröffentlicht 16.09.2026 08:09:11
- Zuletzt bearbeitet 17.09.2026 04:17:59
On affected platforms running Arista EOS, if OpenConfig is configured and running a gNMI server on the system, and if gNSI Pathz is configured and a gNSI Pathz policy is present on the system, then gNMI may fail to correctly enforce the rules in this...
CVE-2026-73461
- EPSS 0.3%
- Veröffentlicht 16.09.2026 08:01:20
- Zuletzt bearbeitet 17.09.2026 04:18:00
On affected EOS platforms with AAA-based gRPC authorization enabled for OpenConfig, gRPC requests of an authenticated user to OpenConfig may use the wrong privilege level, resulting in an authorization using the wrong AAA method list. This does not i...
CVE-2026-73447
- EPSS 0.76%
- Veröffentlicht 16.09.2026 06:04:25
- Zuletzt bearbeitet 17.09.2026 12:18:25
A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full device compromise. An authenticated user can exploit gRPC Network Security Interface (gNSI) Certz service on Arista EOS-based prod...
- EPSS 0.13%
- Veröffentlicht 16.09.2026 02:32:45
- Zuletzt bearbeitet 17.09.2026 18:17:07
On affected platforms running Arista EOS with MLAG Dual Primary Detection configured, an unauthenticated attacker with access to the Dual Primary Detection network segment can send specially crafted packets to interfere with the dual-primary state. I...
- EPSS 0.18%
- Veröffentlicht 15.09.2026 23:20:43
- Zuletzt bearbeitet 16.09.2026 20:17:28
On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject a malformed IS-IS LSP PDU packet can cause the IS-IS graceful restart procedure to terminate prematurely. This may result in traf...
CVE-2026-73459
- EPSS 0.16%
- Veröffentlicht 15.09.2026 23:16:27
- Zuletzt bearbeitet 16.09.2026 20:17:27
On affected platforms running Arista EOS with IS-IS configured, an unauthenticated attacker who can inject a specially crafted IS-IS LSP PDU can cause the legitimate LSP to be unexpectedly purged from the IS-IS link-state database. This may result in...
CVE-2026-73446
- EPSS 0.25%
- Veröffentlicht 15.09.2026 23:08:19
- Zuletzt bearbeitet 16.09.2026 20:17:26
On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an established IS-IS adjacency. This may ...
CVE-2026-73444
- EPSS 0.3%
- Veröffentlicht 15.09.2026 21:11:37
- Zuletzt bearbeitet 16.09.2026 19:17:31
On affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) authentication configured, an unauthenticated attacker with access to the layer 2 network segment on which VRRP is running could bypass VRRP authentication and clai...
CVE-2026-73437
- EPSS 0.2%
- Veröffentlicht 15.09.2026 21:02:49
- Zuletzt bearbeitet 17.09.2026 04:17:57
On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenticated attacker with network access could send a crafted DHCP reply packet from an IP address that is not configured as a helper ad...
CVE-2026-19655
- EPSS 0.19%
- Veröffentlicht 15.09.2026 20:56:46
- Zuletzt bearbeitet 16.09.2026 19:17:10
On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with the information option (Option 82), or with the DHCP server configured with match criteria based on the information option, an una...