External risk intelligence

Arista EOS P4Runtime Arbitrary Code Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.5)

CVE-2026-73453

P4Runtime is a specialized network protocol for software-defined networking, not a public-facing service. It is disabled by default in Arista EOS and is typically used within internal data center or management networks rather than being exposed to the public internet.

Code Injection

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

An unauthenticated client could gain administrative control over a network switch if a specific protocol is enabled. The vulnerability allows for arbitrary code execution under certain conditions, potentially leading to a complete compromise of the affected device. While the protocol is disabled by default, confirming its status is important.

  • Attackers could take full control of switches.
  • This vulnerability affects critical network infrastructure.
  • Confirm P4Runtime status on affected devices.

Attack Path

How an attacker could exploit the issue

An attacker who can access the network where a vulnerable Arista switch operates, and who can trick the switch into initiating a P4Runtime session, could trigger this vulnerability. This allows them to execute arbitrary code on the switch, potentially gaining complete administrative control.

  • Network access required to start.
  • Malicious packet during session initiation.
  • Full administrative control gained.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated client could potentially execute arbitrary code on affected Arista EOS platforms when P4Runtime is enabled, leading to a complete compromise of the network switch. This could impact the switch's control plane and data forwarding capabilities.

  • Network switch control plane.
  • Crafting a malicious packet during session initiation.
  • Complete administrative control over the switch.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given that P4Runtime is disabled by default and not a public-facing service, Arista network and infrastructure teams are likely responsible for managing its configuration and security. The first practical step is to confirm if P4Runtime is enabled on any Arista EOS devices, assess their network exposure, and identify the specific system owners before planning any remediation.

  • Confirm P4Runtime is enabled on devices.
  • Identify accountable network owners.
  • Assess exposure and plan remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Arista EOS and P4Runtime?

Arista EOS is the network operating system powering Arista's data center switches. P4Runtime is a specialized interface used for software-defined networking, allowing controllers to program how the switch handles data packets. While EOS is the core system, P4Runtime is an optional, advanced protocol that adds programmability to the switch's data plane, enabling dynamic control over network traffic.

What does CVE-2026-73453 mean?

This vulnerability is classified as CWE-94, which involves the improper control of generation of code. Essentially, the switch fails to properly validate incoming data during the P4Runtime session setup. An attacker can use this weakness to inject and execute their own unauthorized commands, granting them full administrative power over the device.

How can an attacker trigger this vulnerability?

An attacker needs to reach the switch over the network and interact with the P4Runtime interface. The vulnerability is triggered by sending a specially crafted, malicious packet exactly when a new P4Runtime session is being initiated. Simply having the protocol enabled is not enough; the attacker must actively participate in the session handshake process to exploit the flaw.

Do I need to worry about this if my devices are internal?

Halo Surface Signal indicates that P4Runtime is typically used within internal data center or management networks, making it unlikely to be directly reachable from the public internet. However, security depends on your network's segmentation. If an attacker gains a foothold elsewhere in your internal network and can reach the switch's P4Runtime port, they could potentially target the device.

How do I start addressing this issue?

Your first step is to inventory your Arista EOS devices to determine if P4Runtime is currently enabled, as it is turned off by default. Coordinate with your network engineering team to identify where this protocol is intentionally used. If you find devices with it enabled, verify your internal access controls and monitor configuration changes while you prepare to implement the vendor's recommended updates.

References