{
  "document": {
    "category": "security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "publisher": {
      "category": "vendor",
      "contact_details": "support@arista.com",
      "name": "Arista PSIRT",
      "namespace": "https://www.arista.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Security advisory 169 canonical URL",
        "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24725-security-advisory-0169"
      }
    ],
    "title": "Security Advisory 169",
    "tracking": {
      "current_release_date": "2026-09-17T11:48:19Z",
      "generator": {
        "engine": {
          "name": "Arista Networks SecEng Service CSAF Generator"
        }
      },
      "id": "Arista Networks Security Advisory 169",
      "initial_release_date": "2026-09-17T11:48:19Z",
      "revision_history": [
        {
          "date": "2026-09-17T11:48:19Z",
          "number": "1",
          "summary": "Document created"
        }
      ],
      "status": "draft",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "EOS version 4.34.8",
                    "product": {
                      "name": "EOS version 4.34.8",
                      "product_id": "CSAFPID-0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.35.6",
                    "product": {
                      "name": "EOS version 4.35.6",
                      "product_id": "CSAFPID-1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.34.7.1",
                    "product": {
                      "name": "EOS version 4.34.7.1",
                      "product_id": "CSAFPID-4"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.36.1",
                    "product": {
                      "name": "EOS version 4.36.1",
                      "product_id": "CSAFPID-6"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.33.9",
                    "product": {
                      "name": "EOS version 4.33.9",
                      "product_id": "CSAFPID-5"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.31.0",
                    "product": {
                      "name": "EOS version 4.31.0",
                      "product_id": "CSAFPID-2"
                    }
                  }
                ],
                "category": "product_name",
                "name": "EOS"
              }
            ],
            "category": "product_family",
            "name": "Software Products"
          }
        ],
        "category": "vendor",
        "name": "Arista Networks, Inc."
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-73463",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1602636"
      },
      "notes": [
        {
          "category": "description",
          "text": "On affected platforms running Arista EOS, when multiple gRPC Network Security Interface (gNSI) transports are configured, a race condition in the gNSI Authz service may cause a policy rotation to fail silently. An authenticated user whose access was revoked by the new policy may retain unauthorized access to gRPC interfaces. This does not affect Bootz.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "In order to be vulnerable to CVE-2026-73463, gNSI Authz must be enabled with multiple transports configured:\n\nPlease note that a system may have been affected by this vulnerability if a secondary transport (such as the \"other\" transport in the preceding example) was configured at *any* point. The running configuration on the system may have subsequently been modified to remove this secondary transport. Please refer to the Indicators of Compromise section below to verify the definitive evidence.",
          "title": "1602636: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-2"
        ],
        "fixed": [
          "CSAFPID-0",
          "CSAFPID-1",
          "CSAFPID-4",
          "CSAFPID-5",
          "CSAFPID-6"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-73463"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.33.9",
          "product_ids": [
            "CSAFPID-5"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.34.7.1",
          "product_ids": [
            "CSAFPID-4"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.34.8",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.35.6",
          "product_ids": [
            "CSAFPID-1"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.36.1",
          "product_ids": [
            "CSAFPID-6"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in EOS version 4.31.0",
          "product_ids": [
            "CSAFPID-2"
          ]
        },
        {
          "category": "mitigation",
          "details": "Restrict the set of users that can enable gNSI on OpenConfig / Octa transports via the CLI. We don\u2019t support enabling gNSI via gNMI.Set.\n\nFirstly, configure AAA authorization. The following is an example of configuring AAA authorization for all privilege levels using only the local user database:\n\nNow restrict a sufficient subset of all roles from enabling gNSI services. In the below example, we prohibit just network-operators:"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-2",
            "CSAFPID-6",
            "CSAFPID-0",
            "CSAFPID-4",
            "CSAFPID-5",
            "CSAFPID-1"
          ]
        }
      ],
      "title": "CVE-2026-73463"
    }
  ]
}