{
  "document": {
    "category": "security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "publisher": {
      "category": "vendor",
      "contact_details": "support@arista.com",
      "name": "Arista PSIRT",
      "namespace": "https://www.arista.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Security advisory 162 canonical URL",
        "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24718-security-advisory-0162"
      }
    ],
    "title": "Security Advisory 162",
    "tracking": {
      "current_release_date": "2026-09-17T11:48:15Z",
      "generator": {
        "engine": {
          "name": "Arista Networks SecEng Service CSAF Generator"
        }
      },
      "id": "Arista Networks Security Advisory 162",
      "initial_release_date": "2026-09-17T11:48:15Z",
      "revision_history": [
        {
          "date": "2026-09-17T11:48:15Z",
          "number": "1",
          "summary": "Document created"
        }
      ],
      "status": "draft",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "EOS version 4.34.8",
                    "product": {
                      "name": "EOS version 4.34.8",
                      "product_id": "CSAFPID-0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.35.6",
                    "product": {
                      "name": "EOS version 4.35.6",
                      "product_id": "CSAFPID-1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.30.2",
                    "product": {
                      "name": "EOS version 4.30.2",
                      "product_id": "CSAFPID-6"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.33.9",
                    "product": {
                      "name": "EOS version 4.33.9",
                      "product_id": "CSAFPID-4"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.34.7.1",
                    "product": {
                      "name": "EOS version 4.34.7.1",
                      "product_id": "CSAFPID-3"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.36.1",
                    "product": {
                      "name": "EOS version 4.36.1",
                      "product_id": "CSAFPID-5"
                    }
                  }
                ],
                "category": "product_name",
                "name": "EOS"
              }
            ],
            "category": "product_family",
            "name": "Software Products"
          }
        ],
        "category": "vendor",
        "name": "Arista Networks, Inc."
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-73447",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1602632"
      },
      "notes": [
        {
          "category": "description",
          "text": "A vulnerability in the gRPC Network Security Interface (gNSI) Certz service on Arista EOS-based products allows an authenticated user to escalate its privilege to execute arbitrary OS commands via a crafted Certz Rotate request. The Bootz service is also affected.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "In order to be vulnerable to CVE-2026-73447, gNSI Certz must be configured:\n\nOr the system must use Bootz for initial provisioning.\n\n### Indicators of Compromise\n\nauditd can be configured to monitor process creation like in the following snippet:\n\nRun the following command in bash to search for suspicious `openssl` child processes spawned by OpenConfig/Octa(assuming the OpenConfig/Octa process has pid 123):\n\nNote: Legitimate system certificate rotations may, but unlikely, spawn openssl processes. Correlate findings with unauthorized gNSI Rotate RPC calls or unexpected administrative activity before concluding exploitation occurred.\n\n### Mitigation\n\nThere is one mitigation for Bootz:\n\n- Do not include any Certificates (X509 PEM data) when sending the initial CertzProfile via Bootz.\n\nThere are two mitigations for the Certz service:\n\n1. Disable gNSI Certz. This fully mitigates the bug from affecting gNSI Certz, but will require manual ssl profile management. For more information on ssl profile management, see [https://www.arista.com/en/support/toi/eos-4-15-0f/13673-ssl-certificate-and-key-management](https://www.arista.com/en/support/toi/eos-4-15-0f/13673-ssl-certificate-and-key-management).\n2. Use a gNSI Authz policy that restricts gNSI Certz use to only those who strictly need it. This doesn\u2019t fully mitigate the bug, but allows for the use of gNSI Certz. Firstly, enable gNSI Authz:\n\nThen, upload a strict policy. Below is an example policy that restricts Certz\u2019s Rotate RPC to user \u201cNeo\u201d.\n\nIdeally, this policy would be uploaded via a gNSI client for correct *version* and *created-on* metadata handling. However, we can also write directly to the active policy file, like in the following example:\n\nFor more information on gNSI Authz, see [https://www.arista.com/en/support/toi/eos-4-31-0f/18445-support-for-gnsi-grpc-network-security-interface\\#authz](https://www.arista.com/en/support/toi/eos-4-31-0f/18445-support-for-gnsi-grpc-network-security-interface#authz).\n\n### Resolution\n\nThe recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below. For more information about upgrading see [EOS User Manual: Upgrades and Downgrades](https://www.arista.com/en/um-eos/eos-upgrades-and-downgrades)\n\nCVE-2026-73447 has been fixed in the following releases:\n\n* 4.36.1F and later releases in the 4.36.x train\n* 4.35.6M and later releases in the 4.35.x train\n* 4.34.7.1M and later releases in the 4.34.x train\n* 4.33.9M and later releases in the 4.33.x train\n\n### Hotfix\n\nNo hotfix is available for this issue.\n\n### For More Information\n\nIf you require further assistance, or if you have any further questions regarding this security notice, please contact the Arista Networks Technical Assistance Center (TAC) by one of the following methods:\n\n### Open a Service Request\n\nContact information needed to open a new service request may be found at:\n\n[https://www.arista.com/en/support/customer-support](https://www.arista.com/en/support/customer-support)\n<!-- END TAB1: Tab 1 -->",
          "title": "1602632: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-6"
        ],
        "fixed": [
          "CSAFPID-0",
          "CSAFPID-1",
          "CSAFPID-3",
          "CSAFPID-4",
          "CSAFPID-5"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-73447"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.33.9",
          "product_ids": [
            "CSAFPID-4"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.34.7.1",
          "product_ids": [
            "CSAFPID-3"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.34.8",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.35.6",
          "product_ids": [
            "CSAFPID-1"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.36.1",
          "product_ids": [
            "CSAFPID-5"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in EOS version 4.30.2",
          "product_ids": [
            "CSAFPID-6"
          ]
        },
        {
          "category": "mitigation",
          "details": "There is one mitigation for Bootz:\n\n- Do not include any Certificates (X509 PEM data) when sending the initial CertzProfile via Bootz.\n\nThere are two mitigations for the Certz service:\n\n1. Disable gNSI Certz. This fully mitigates the bug from affecting gNSI Certz, but will require manual ssl profile management. For more information on ssl profile management, see [https://www.arista.com/en/support/toi/eos-4-15-0f/13673-ssl-certificate-and-key-management](https://www.arista.com/en/support/toi/eos-4-15-0f/13673-ssl-certificate-and-key-management).\n2. Use a gNSI Authz policy that restricts gNSI Certz use to only those who strictly need it. This doesn\u2019t fully mitigate the bug, but allows for the use of gNSI Certz. Firstly, enable gNSI Authz:\n\nThen, upload a strict policy. Below is an example policy that restricts Certz\u2019s Rotate RPC to user \u201cNeo\u201d.\n\nIdeally, this policy would be uploaded via a gNSI client for correct *version* and *created-on* metadata handling. However, we can also write directly to the active policy file, like in the following example:\n\nFor more information on gNSI Authz, see [https://www.arista.com/en/support/toi/eos-4-31-0f/18445-support-for-gnsi-grpc-network-security-interface\\#authz](https://www.arista.com/en/support/toi/eos-4-31-0f/18445-support-for-gnsi-grpc-network-security-interface#authz).\n\n### Resolution\n\nThe recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below. For more information about upgrading see [EOS User Manual: Upgrades and Downgrades](https://www.arista.com/en/um-eos/eos-upgrades-and-downgrades)\n\nCVE-2026-73447 has been fixed in the following releases:\n\n* 4.36.1F and later releases in the 4.36.x train\n* 4.35.6M and later releases in the 4.35.x train\n* 4.34.7.1M and later releases in the 4.34.x train\n* 4.33.9M and later releases in the 4.33.x train\n\n### Hotfix\n\nNo hotfix is available for this issue.\n\n### For More Information\n\nIf you require further assistance, or if you have any further questions regarding this security notice, please contact the Arista Networks Technical Assistance Center (TAC) by one of the following methods:\n\n### Open a Service Request\n\nContact information needed to open a new service request may be found at:\n\n[https://www.arista.com/en/support/customer-support](https://www.arista.com/en/support/customer-support)\n<!-- END TAB1: Tab 1 -->"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-3",
            "CSAFPID-6",
            "CSAFPID-0",
            "CSAFPID-4",
            "CSAFPID-5",
            "CSAFPID-1"
          ]
        }
      ],
      "title": "CVE-2026-73447"
    }
  ]
}