Sceawere

Vulnerability Detail

CVE-2026-73454UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Arista EOS gNSI Privilege Escalation

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
1d ago
Vendor
Arista Networks
Product
EOS
Attack Type
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

On affected platforms running Arista EOS with gRPC Network Security Interface (gNSI) Credentialz configured, a specially crafted request can cause unintended modifications to the target account's properties. This may result in the account being assigned elevated privileges or access beyond what an administrator intended.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-09-16T09:17:05.020Z",
  "pubdate": "2026-09-16T09:17:05.020Z",
  "executiveSummary": "This vulnerability involves an improper authorization or input validation flaw within the gRPC Network Security Interface (gNSI) Credentialz service in Arista EOS.\nThe vulnerability allows an attacker to manipulate account properties via specially crafted requests, leading to unauthorized privilege escalation.\nBy targeting the Credentialz management functionality, an authenticated user or attacker with access to the gNSI interface can modify account attributes beyond their intended administrative scope.\nThe primary impact is the unauthorized assignment of elevated privileges to a target account, effectively bypassing security controls defined by the network administrator.\nThis represents a high-risk security flaw, as it facilitates horizontal or vertical privilege escalation, potentially granting an attacker full administrative control over the affected network device.\nExploitation requires the gNSI Credentialz feature to be explicitly enabled on the platform, and the attacker must be capable of issuing gRPC requests to the interface.\nThe vulnerability highlights a critical failure in the validation of administrative operations performed through the gNSI service, necessitating immediate remediation to maintain device integrity and access control consistency.",
  "technicalDetails": "The vulnerability resides within the gRPC Network Security Interface (gNSI) subsystem of Arista EOS, specifically concerning the Credentialz service responsible for managing account security objects and properties.\nThe root cause is an insufficient validation of request parameters during the processing of gRPC calls directed at the Credentialz API. When the gNSI Credentialz configuration is active, the service endpoint fails to adequately enforce authorization boundaries when processing specific modification requests.\nAn attacker leverages this flaw by constructing a malformed or specially crafted gNSI request. By injecting specific attributes or modifying expected parameters within the gRPC payload, the attacker influences the underlying state-change operation within the device's identity management system.\nThe exploitation flow proceeds as follows: First, the attacker establishes a connection to the device's gNSI endpoint. Second, the attacker issues a request targeted at the Credentialz service intended to modify an account property. Third, because the system fails to correctly validate the modification parameters against the requester's authorized scope, the service executes the operation as if it originated from a privileged context.\nThis sequence results in the target account—which may be the attacker's own account or another existing account—being updated with elevated access levels or sensitive property modifications not permitted by existing administrative policy.\nThe vulnerable component is the gNSI Credentialz implementation within Arista EOS. Because the interface utilizes gRPC, the attack is performed over the network, making the vulnerability exploitable from any location with connectivity to the gNSI management interface.\nPost-exploitation, the attacker gains the permissions assigned to the modified account. Given that the modification can involve escalating privileges, an attacker can effectively compromise the security posture of the EOS instance, enabling further unauthorized configuration changes, exfiltration of sensitive information, or complete device takeover.\nAuthentication requirements depend on the gNSI setup; however, once initial access to the interface is achieved, the Credentialz service lacks the granular per-request integrity checks required to prevent unauthorized property manipulation. This flaw undermines the core premise of delegated identity management provided by the gNSI Credentialz framework, as it allows for the subversion of the intended security policy regarding account attribute management."
}