CVE-2026-73453
10 CRITICALPublished 2026-09-16 · Updated 2026-09-17
AI risk analysis
- Summary
- An unauthenticated attacker can exploit a flaw in Arista EOS P4Runtime to achieve arbitrary code execution, granting full administrative control over the switch.
- Exploitability
- Exploitation requires crafting a malicious packet during P4Runtime session initiation, making it technically challenging but feasible under specific conditions.
- Blast radius
- If exploited, the attacker can gain complete control over the switch, potentially leading to widespread network disruption and data compromise.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Disable P4Runtime in Arista EOS to mitigate the risk, as it is disabled by default.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code execution under certain conditions on affected platforms running Arista EOS configured with P4Runtime. P4Runtime is disabled by default in Arista EOS. By crafting a malicious packet during the initiation of a P4Runtime session, an attacker can obtain complete administrative control over the compromised switch. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-94
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-73464
- HIGHCVE-2026-58197PoC
- CRITICALCVE-2026-86106
- HIGHCVE-2026-94184
- HIGHCVE-2026-100864PoC
- HIGHCVE-2026-100865PoC
- HIGHCVE-2026-19804
- HIGHCVE-2026-4327
Related by shared AI tags and CWE weakness class. Browse the full archive.