{
  "document": {
    "category": "security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "publisher": {
      "category": "vendor",
      "contact_details": "support@arista.com",
      "name": "Arista PSIRT",
      "namespace": "https://www.arista.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Security advisory 170 canonical URL",
        "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24726-security-advisory-0170"
      }
    ],
    "title": "Security Advisory 170",
    "tracking": {
      "current_release_date": "2026-09-17T11:48:19Z",
      "generator": {
        "engine": {
          "name": "Arista Networks SecEng Service CSAF Generator"
        }
      },
      "id": "Arista Networks Security Advisory 170",
      "initial_release_date": "2026-09-17T11:48:19Z",
      "revision_history": [
        {
          "date": "2026-09-17T11:48:19Z",
          "number": "1",
          "summary": "Document created"
        }
      ],
      "status": "draft",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "EOS version 4.34.8",
                    "product": {
                      "name": "EOS version 4.34.8",
                      "product_id": "CSAFPID-1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.24.0",
                    "product": {
                      "name": "EOS version 4.24.0",
                      "product_id": "CSAFPID-3"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.34.7.1",
                    "product": {
                      "name": "EOS version 4.34.7.1",
                      "product_id": "CSAFPID-6"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.33.9",
                    "product": {
                      "name": "EOS version 4.33.9",
                      "product_id": "CSAFPID-0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.27.1",
                    "product": {
                      "name": "EOS version 4.27.1",
                      "product_id": "CSAFPID-8"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.35.6",
                    "product": {
                      "name": "EOS version 4.35.6",
                      "product_id": "CSAFPID-5"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.36.1",
                    "product": {
                      "name": "EOS version 4.36.1",
                      "product_id": "CSAFPID-2"
                    }
                  }
                ],
                "category": "product_name",
                "name": "EOS"
              }
            ],
            "category": "product_family",
            "name": "Software Products"
          }
        ],
        "category": "vendor",
        "name": "Arista Networks, Inc."
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-19640",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1602635,1602639"
      },
      "notes": [
        {
          "category": "description",
          "text": "On affected platforms running Arista EOS, an authenticated user with access to the gNMI(gRPC Network Management Interface) may receive incorrect authorization results, potentially allowing access beyond their currently assigned permissions.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "In order to be vulnerable to CVE-2026-19640, OpenConfig with authorized requests must be configured:",
          "title": "1602635: Required Config for Exploitation"
        },
        {
          "category": "other",
          "text": "In order to be vulnerable to CVE-2026-19640, OpenConfig with authorized requests must be configured:",
          "title": "1602639: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-3"
        ],
        "fixed": [
          "CSAFPID-0",
          "CSAFPID-1",
          "CSAFPID-2",
          "CSAFPID-5",
          "CSAFPID-6"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-19640"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.33.9",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.34.7.1",
          "product_ids": [
            "CSAFPID-6"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.34.8",
          "product_ids": [
            "CSAFPID-1"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.35.6",
          "product_ids": [
            "CSAFPID-5"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.36.1",
          "product_ids": [
            "CSAFPID-2"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in EOS version 4.24.0",
          "product_ids": [
            "CSAFPID-3"
          ]
        },
        {
          "category": "mitigation",
          "details": "The vulnerability can be mitigated by performing both of the following actions.\n\n1. Kill gNMI subscriptions after AAA authorization policy changes. Run the following command to kill gNMI subscriptions to OpenConfig/Octa on port 6030. If a different port than the default of 6030 is being used for OpenConfig/Octa, adjust accordingly to that port:\n\nNote: the port that OpenConfig/Octa is running the gNMI transport on is available in the output of the `show man api gnmi` CLI command (see above under the `Server:` field)\n\n2. Use username and password based authentication (as opposed to mTLS) for gNMI requests to OpenConfig/Octa. The following command is an example using Arista\u2019s gNMI client:\n\n\t\n\nFor a transport running mTLS, mTLS can be disabled for this transport by any of the configurations described below:\n\na. Configure the SSL profile to use TLS instead of mTLS. This can be done by removing the trusted certificates from the SSL profile, using the \u201c`no trust certificate <name>`\u201d CLI command within the SSL profile.\n\nFor example, if an SSL profile has configuration like:\n\nThen this profile can be changed from mTLS to TLS by removing each of the trusted certificates:\n\nNote that if other transports or servers on the system have configured to use this SSL profile, then the above configuration will also cause them to transition from mTLS to TLs.\n\nb. Configure the OpenConfig/Octa transport to use an insecure server instead of mTLS, by removing the SSL profile config from the \u201c`transport grpc <name>`\u201d mode. This can be done by running the \u201c`no ssl profile`\u201d command as shown:\n\nWhen this is done, the show command will display that no SSL profile is configured:"
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.33.9",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.34.7.1",
          "product_ids": [
            "CSAFPID-6"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.34.8",
          "product_ids": [
            "CSAFPID-1"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.35.6",
          "product_ids": [
            "CSAFPID-5"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.36.1",
          "product_ids": [
            "CSAFPID-2"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in EOS version 4.27.1",
          "product_ids": [
            "CSAFPID-8"
          ]
        },
        {
          "category": "mitigation",
          "details": "The vulnerability can be mitigated by performing both of the following actions.\n\n1. Kill gNMI subscriptions after AAA authorization policy changes. Run the following command to kill gNMI subscriptions to OpenConfig/Octa on port 6030. If a different port than the default of 6030 is being used for OpenConfig/Octa, adjust accordingly to that port:\n\nNote: the port that OpenConfig/Octa is running the gNMI transport on is available in the output of the `show man api gnmi` CLI command (see above under the `Server:` field)\n\n2. Use username and password based authentication (as opposed to mTLS) for gNMI requests to OpenConfig/Octa. The following command is an example using Arista\u2019s gNMI client:\n\n\t\n\nFor a transport running mTLS, mTLS can be disabled for this transport by any of the configurations described below:\n\na. Configure the SSL profile to use TLS instead of mTLS. This can be done by removing the trusted certificates from the SSL profile, using the \u201c`no trust certificate <name>`\u201d CLI command within the SSL profile.\n\nFor example, if an SSL profile has configuration like:\n\nThen this profile can be changed from mTLS to TLS by removing each of the trusted certificates:\n\nNote that if other transports or servers on the system have configured to use this SSL profile, then the above configuration will also cause them to transition from mTLS to TLs.\n\nb. Configure the OpenConfig/Octa transport to use an insecure server instead of mTLS, by removing the SSL profile config from the \u201c`transport grpc <name>`\u201d mode. This can be done by running the \u201c`no ssl profile`\u201d command as shown:\n\nWhen this is done, the show command will display that no SSL profile is configured:"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.2,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-8",
            "CSAFPID-5",
            "CSAFPID-6",
            "CSAFPID-3",
            "CSAFPID-0",
            "CSAFPID-2",
            "CSAFPID-1"
          ]
        }
      ],
      "title": "CVE-2026-19640"
    }
  ]
}