External risk intelligence

Arista EOS gNSI and Bootz Privilege Escalation and Command Execution

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-73447

The vulnerability affects gNSI and Bootz services on network infrastructure devices. These services are typically used for administrative configuration and device management within internal network operations, and while network-reachable, they are not intended for public internet exposure.

OS Command Injection

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability exists in network devices that could allow a privileged attacker to execute arbitrary commands with full system control. This issue impacts specific administrative services, and while it requires existing access, successful exploitation could lead to a complete device compromise. The main concern is confirming relevance and exposure within our environment.

  • Attackers could gain full control of affected devices.
  • Leadership should remember this impacts critical network infrastructure.
  • Confirm relevance and understand potential exposure.

Attack Path

How an attacker could exploit the issue

A privileged attacker with authenticated access can exploit a vulnerability in the Certz service, and potentially the Bootz service, of Arista EOS-based products. By sending a specially crafted request to the gRPC Network Security Interface (gNSI), the attacker can escalate their privileges and execute arbitrary operating system commands, leading to complete device compromise.

  • Requires authenticated user access.
  • Triggered by a crafted Certz Rotate request.
  • Leads to full device compromise.

Live Threat

Current exploitation, exposure, and threat context

A privileged attacker with authenticated access could exploit the gRPC Network Security Interface (gNSI) Certz service, or the Bootz service, to execute arbitrary OS commands with root privileges. This could lead to a full device compromise when supported by the advisory's conditions.

  • Root privileges and full device compromise.
  • Authenticated users exploit gRPC services.
  • Complete takeover of affected devices.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Arista EOS products requires immediate attention from infrastructure and platform teams responsible for network device management. The first step is to inventory all Arista devices, identify those with the affected services exposed, and confirm their business criticality. Subsequently, engage the platform or network security teams to plan and execute remediation, coordinating with the vendor as needed.

  • Own by Infrastructure/Platform teams.
  • Verify gNSI/Bootz service exposure.
  • Plan remediation with vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Arista EOS and what are gNSI and Bootz?

Arista EOS is the network operating system powering Arista's switches and routers, commonly used in high-performance data centers. gNSI (gRPC Network Security Interface) and Bootz are administrative services built into the OS. They provide programmatic ways for network teams to manage security certificates and automate the device boot process across large infrastructures.

What is the nature of the vulnerability in CVE-2026-73447?

This vulnerability is classified as CWE-78, or OS Command Injection. It means the software fails to properly filter commands before executing them. In the context of CVE-2026-73447, it allows an attacker to trick the Certz or Bootz services into running unauthorized system-level commands, effectively granting them full root control over the network device.

How is this vulnerability triggered?

The issue is triggered when an already authenticated user sends a specifically crafted 'Rotate' request to the Certz service. It is important to note that this is not a blind attack; it requires valid credentials to access the service first. Regular network traffic that does not interact with these specific administrative gRPC interfaces will not trigger the command execution.

Is my device at risk based on Halo Surface Signal?

Halo Surface Signal indicates that the risk is unlikely for most organizations because gNSI and Bootz services are designed for internal management, not for public internet exposure. While these services are network-reachable, they should reside within protected, internal administrative segments rather than being accessible from the open web.

What should I do if I run Arista EOS?

First, create an inventory of all your Arista hardware to identify which devices are running these services. Prioritize your most critical network infrastructure and coordinate with your internal platform teams to review access controls. Consult the official Arista security advisory for the specific software updates or configuration changes needed to secure your environment.

References