A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full device compromise. An authenticated user can exploit gRPC Network Security Interface (gNSI) Certz service on Arista EOS-based products to escalate privileges and execute arbitrary OS commands via a crafted Certz Rotate request. The Bootz service is also affected.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-16 07:16
Updated : 2026-09-16 07:16
NVD link : CVE-2026-73447
Mitre link : CVE-2026-73447
CVE.ORG link : CVE-2026-73447
JSON object : View
Products Affected
No product.
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
