VORANT. Threat Intelligence Sign in Get the full feed

Arista EOS gNPSI flaws enable code injection

routine vulnerability telecommunicationstechnologyinfrastructure

Arista patched two EOS vulnerabilities in gNPSI processing that can allow unauthenticated code injection and plaintext credential leakage in logs.

Arista has released updates for its EOS switch platform addressing two vulnerabilities related to the gNPSI (gRPC Network Packet Streaming Interface) service. CVE-2026-73456 is a code injection flaw in the handling of gNPSI requests: an unauthenticated attacker with network access to the gNPSI service can send a specially crafted request to execute arbitrary code, potentially gaining full administrative control over the affected switch. This is only exploitable when gNPSI is enabled together with specific TLS and authentication configurations.

CVE-2026-73457 is an information-disclosure issue where gNPSI client credentials, including passwords, can be written in plaintext to local or remote accounting logs. An attacker with sufficient privileges to access those logs could read the exposed credentials. According to Arista, exploitation requires gNPSI to be enabled and the EosRpcAuth trace facility to be explicitly activated.

gNPSI is disabled by default, meaning switches running factory/default configurations are not vulnerable to either issue. There is no indication of in-the-wild exploitation; this is a vendor-issued patch advisory. Defenders running Arista EOS should check whether gNPSI is enabled and, if so, apply the vendor updates, review TLS/authentication settings for the service, and audit accounting logs for exposed plaintext credentials, disabling the EosRpcAuth trace facility unless required.

Mentioned in this report

Vulnerabilities CVE-2026-73456CVE-2026-73457

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0366.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free