← Back to search

CVE-2026-73453

10 CRITICAL

Published 2026-09-16 · Updated 2026-09-17

AI risk analysis

Summary
An unauthenticated attacker can exploit a flaw in Arista EOS P4Runtime to achieve arbitrary code execution, granting full administrative control over the switch.
Exploitability
Exploitation requires crafting a malicious packet during P4Runtime session initiation, making it technically challenging but feasible under specific conditions.
Blast radius
If exploited, the attacker can gain complete control over the switch, potentially leading to widespread network disruption and data compromise.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable P4Runtime in Arista EOS to mitigate the risk, as it is disabled by default.
rceauth-bypassnetwork

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code execution under certain conditions on affected platforms running Arista EOS configured with P4Runtime. P4Runtime is disabled by default in Arista EOS. By crafting a malicious packet during the initiation of a P4Runtime session, an attacker can obtain complete administrative control over the compromised switch. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-94

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.