{"id":"CVE-2026-73453","published":"2026-09-16T10:16:52.043","lastModified":"2026-09-17T04:17:59.823","description":"An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code execution under certain conditions on affected platforms running Arista EOS configured with P4Runtime. P4Runtime is disabled by default in Arista EOS. By crafting a malicious packet during the initiation of a P4Runtime session, an attacker can obtain complete administrative control over the compromised switch.\n\nThis issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.","cvssScore":10,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-94"],"vendors":[],"products":[],"references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24730-security-advisory-0174","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"An unauthenticated attacker can exploit a flaw in Arista EOS P4Runtime to achieve arbitrary code execution, granting full administrative control over the switch.","exploitability":"Exploitation requires crafting a malicious packet during P4Runtime session initiation, making it technically challenging but feasible under specific conditions.","blast_radius":"If exploited, the attacker can gain complete control over the switch, potentially leading to widespread network disruption and data compromise.","remediation":"Disable P4Runtime in Arista EOS to mitigate the risk, as it is disabled by default.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","auth-bypass","network"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:56:20.968Z"}}