{
  "document": {
    "category": "security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "publisher": {
      "category": "vendor",
      "contact_details": "support@arista.com",
      "name": "Arista PSIRT",
      "namespace": "https://www.arista.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Security advisory 158 canonical URL",
        "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24714-security-advisory-0158"
      }
    ],
    "title": "Security Advisory 158",
    "tracking": {
      "current_release_date": "2026-09-17T11:48:13Z",
      "generator": {
        "engine": {
          "name": "Arista Networks SecEng Service CSAF Generator"
        }
      },
      "id": "Arista Networks Security Advisory 158",
      "initial_release_date": "2026-09-17T11:48:13Z",
      "revision_history": [
        {
          "date": "2026-09-17T11:48:13Z",
          "number": "1",
          "summary": "Document created"
        }
      ],
      "status": "interim",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "EOS version 4.35.6",
                    "product": {
                      "name": "EOS version 4.35.6",
                      "product_id": "CSAFPID-1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.34.8",
                    "product": {
                      "name": "EOS version 4.34.8",
                      "product_id": "CSAFPID-2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.36.2",
                    "product": {
                      "name": "EOS version 4.36.2",
                      "product_id": "CSAFPID-3"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.34.2",
                    "product": {
                      "name": "EOS version 4.34.2",
                      "product_id": "CSAFPID-0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "EOS"
              }
            ],
            "category": "product_family",
            "name": "Software Products"
          }
        ],
        "category": "vendor",
        "name": "Arista Networks, Inc."
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-73456",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1823956"
      },
      "notes": [
        {
          "category": "description",
          "text": "Under certain circumstances, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "In order to be vulnerable to CVE-2026-73456, one of the following conditions must be met:\n\nA gNPSI transport must be configured to perform TLS (server verification) and metadata authentication has to be enabled.\n\nOr mTLS enabled with *x509-common-name* authentication configured.\n\nIn order to be vulnerable to CVE-2026-73457, gNPSI must be configured with trace facility EosRpcAuth enabled explicitly:\n\nSystems remain unaffected by either CVE-2026-73456 or CVE-2026-73457 if gNPSI is not enabled, which is the default configuration.",
          "title": "1823956: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-0"
        ],
        "fixed": [
          "CSAFPID-1",
          "CSAFPID-2",
          "CSAFPID-3"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-73456"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.34.8",
          "product_ids": [
            "CSAFPID-2"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.35.6",
          "product_ids": [
            "CSAFPID-1"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.36.2",
          "product_ids": [
            "CSAFPID-3"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in EOS version 4.34.2",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "mitigation",
          "details": "To secure the agent against both CVE-2026-73456 and CVE-2026-73457, the service must be configured to use *mutual TLS* and only *x509-spiffe* authentication must be enabled.\n\nLogs are disabled by default, including the affected facility `EosRpcAuth`.To mitigate CVE-2026-73457, ensure the facility `EosRpcAuth` status is set to disabled. The command below can be used to restore all Gnpsi agent tracing to its default setting.\n\nShould it be determined that sensitive information has been logged, the affected log files must be truncated and any compromised secrets rotated to prevent gNPSI client credentials leaking.\n\nUse the following commands to clean up Gnpsi log files:\n\nThen use the following commands to clean up previously rotated old log files:"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 10.0,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-1",
            "CSAFPID-0",
            "CSAFPID-2",
            "CSAFPID-3"
          ]
        }
      ],
      "title": "CVE-2026-73456"
    },
    {
      "cve": "CVE-2026-73457",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1824885"
      },
      "notes": [
        {
          "category": "description",
          "text": "Under certain circumstances, the gNPSI client credentials might be logged in clear text, in local or remote accounting logs to authenticated users.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "In order to be vulnerable to CVE-2026-73456, one of the following conditions must be met:\n\nA gNPSI transport must be configured to perform TLS (server verification) and metadata authentication has to be enabled.\n\nOr mTLS enabled with *x509-common-name* authentication configured.\n\nIn order to be vulnerable to CVE-2026-73457, gNPSI must be configured with trace facility EosRpcAuth enabled explicitly:\n\nSystems remain unaffected by either CVE-2026-73456 or CVE-2026-73457 if gNPSI is not enabled, which is the default configuration.",
          "title": "1824885: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-0"
        ],
        "fixed": [
          "CSAFPID-1",
          "CSAFPID-2",
          "CSAFPID-3"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-73457"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.34.8",
          "product_ids": [
            "CSAFPID-2"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.35.6",
          "product_ids": [
            "CSAFPID-1"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.36.2",
          "product_ids": [
            "CSAFPID-3"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in EOS version 4.34.2",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "mitigation",
          "details": "To secure the agent against both CVE-2026-73456 and CVE-2026-73457, the service must be configured to use *mutual TLS* and only *x509-spiffe* authentication must be enabled.\n\nLogs are disabled by default, including the affected facility `EosRpcAuth`.To mitigate CVE-2026-73457, ensure the facility `EosRpcAuth` status is set to disabled. The command below can be used to restore all Gnpsi agent tracing to its default setting.\n\nShould it be determined that sensitive information has been logged, the affected log files must be truncated and any compromised secrets rotated to prevent gNPSI client credentials leaking.\n\nUse the following commands to clean up Gnpsi log files:\n\nThen use the following commands to clean up previously rotated old log files:"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-1",
            "CSAFPID-0",
            "CSAFPID-2",
            "CSAFPID-3"
          ]
        }
      ],
      "title": "CVE-2026-73457"
    }
  ]
}