{
  "document": {
    "category": "security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "publisher": {
      "category": "vendor",
      "contact_details": "support@arista.com",
      "name": "Arista PSIRT",
      "namespace": "https://www.arista.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Security advisory 164 canonical URL",
        "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24720-security-advisory-0164"
      }
    ],
    "title": "Security Advisory 164",
    "tracking": {
      "current_release_date": "2026-09-17T11:48:16Z",
      "generator": {
        "engine": {
          "name": "Arista Networks SecEng Service CSAF Generator"
        }
      },
      "id": "Arista Networks Security Advisory 164",
      "initial_release_date": "2026-09-17T11:48:16Z",
      "revision_history": [
        {
          "date": "2026-09-17T11:48:16Z",
          "number": "1",
          "summary": "Document created"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "EOS version 4.34.7",
                    "product": {
                      "name": "EOS version 4.34.7",
                      "product_id": "CSAFPID-1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.33.9",
                    "product": {
                      "name": "EOS version 4.33.9",
                      "product_id": "CSAFPID-0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.35.6",
                    "product": {
                      "name": "EOS version 4.35.6",
                      "product_id": "CSAFPID-5"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.36.1",
                    "product": {
                      "name": "EOS version 4.36.1",
                      "product_id": "CSAFPID-2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.33.2",
                    "product": {
                      "name": "EOS version 4.33.2",
                      "product_id": "CSAFPID-3"
                    }
                  }
                ],
                "category": "product_name",
                "name": "EOS"
              }
            ],
            "category": "product_family",
            "name": "Software Products"
          }
        ],
        "category": "vendor",
        "name": "Arista Networks, Inc."
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-73439",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1602638"
      },
      "notes": [
        {
          "category": "description",
          "text": "On affected platforms running Arista EOS, if OpenConfig is configured and running a gNMI (gRPC Network Management Interface) server on the system, and if gNSI (gRPC Network Security Interface) Pathz is configured and a gNSI Pathz policy is present on the system, then gNMI may fail to correctly enforce the rules in this policy if both a group rule and a user rule for the same path is present in the policy. Under certain conditions, this can lead to an authenticated user gaining unauthorized permission to read or write gNMI paths that the Pathz policy is intended to restrict.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "In order to be vulnerable to CVE-2026-73439, all of the following conditions must be met:\n\n- OpenConfig must be configured with a gNMI transport started\n- gNSI must be configured with the gNSI Pathz service enabled.\n- A pathz policy must be present on the system, with at least one group rule in the policy and at least one user rule in the policy.\n\nIf OpenConfig is configured with a gNMI transport, the running configuration will include:\n\nWhere <name> is the name of the transport.\n\nIf gNSI is configured with the gNSI Pathz service enforced, the running configuration will include:\n\nThe config may also reference a gRPC transport which would be used to run the gNSI Pathz service and perform policy rotation:\n\nIf a Pathz policy (if present on the system) will be at the path `/persist/sys/gnsi/pathz/policy.json`\n\nTo check for the presence of the policy here, run the following commands:\n\nThe Pathz policy must contain at least one group rule and at least one user rule for the same path, so the `/persist/sys/gnsi/pathz/policy.json` file will contain a rule entry with \u201cgroup\u201d specified as the principal, and another with \u201cuser\u201d specified as the principal, and the same path used in both instances.\n\nFor example the following rule uses the group \u201csome-group\u201d as the principal, and /system as the path:\n\nAnd the following rule uses the user \u201cbob\u201d as the principal and /system as the path:",
          "title": "1602638: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-3"
        ],
        "fixed": [
          "CSAFPID-0",
          "CSAFPID-1",
          "CSAFPID-2",
          "CSAFPID-5"
        ]
      },
      "references": [
        {
          "category": "external",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-73439",
          "summary": "MITRE"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.33.9",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.34.7",
          "product_ids": [
            "CSAFPID-1"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.35.6",
          "product_ids": [
            "CSAFPID-5"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.36.1",
          "product_ids": [
            "CSAFPID-2"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in EOS version 4.33.2",
          "product_ids": [
            "CSAFPID-3"
          ]
        },
        {
          "category": "mitigation",
          "details": "One possible mitigation to this is to disable gNSI Pathz. \n\nThis can be done with the following configuration:\n\nAnother possible mitigation is to push a new gNSI Pathz policy to the system (using the gNSI Pathz Rotate RPC), where this policy does not contain any group rules. \n\nTo push a new policy, initiate a Pathz Rotate RPC with your client. Using grpcurl, to an insecure server for a user with no password, this would look like:\n\nFor example, to push a policy allowing the users \u201calice\u201d and \u201cbob\u201d  access to `/system`, push a policy like so:\n\nNote the rules are using the \u201cuser\u201d principal, so as to avoid being subject to this CVE, and that rules are duplicated for each user, rather than putting these in a group."
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-5",
            "CSAFPID-3",
            "CSAFPID-0",
            "CSAFPID-2",
            "CSAFPID-1"
          ]
        }
      ],
      "title": "CVE-2026-73439"
    }
  ]
}