External risk intelligence

Arista EOS gRPC Network Packet Sampling Interface Arbitrary Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-73456

The vulnerability affects the gRPC Network Packet Sampling Interface (gNPSI) in Arista EOS. While network-reachable, this interface is typically used for internal network telemetry and management within a data center or administrative network. Public internet exposure of such infrastructure interfaces is uncommon and contrary to standard secure deployment practices.

Code Injection

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

An unauthenticated client could execute arbitrary code on Arista switches running gRPC Network Packet Sampling Interface (gNPSI) if this feature is enabled, potentially leading to a complete compromise of the affected device.

  • Malicious code could run on network switches.
  • Attackers gain full administrative control of switches.
  • Confirm relevance and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker could target a network device running Arista EOS with the gRPC Network Packet Sampling Interface (gNPSI) enabled. By sending a specially crafted, unauthenticated request to this interface, an attacker could potentially execute arbitrary code on the device, leading to complete administrative control.

  • Network access to gNPSI is required.
  • A malicious gNPSI request triggers the vulnerability.
  • Full administrative control of the switch can be gained.

Live Threat

Current exploitation, exposure, and threat context

When Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) is enabled, an unauthenticated client could execute arbitrary code, potentially allowing an attacker full administrative control over the affected network switch.

  • Network switch administrative control.
  • Malicious gRPC request sent to gNPSI.
  • Full compromise of network device.

Operational Fix

Recommended remediation, mitigation, and detection steps

To address this critical vulnerability, the platform or infrastructure team responsible for Arista network devices should take the lead, in coordination with the network security team. The first practical step is to identify all Arista devices running the affected software, confirm if gRPC Network Packet Sampling Interface (gNPSI) is enabled, and assess their network exposure and business criticality. This will help prioritize remediation efforts, which may involve configuration changes or vendor engagement.

  • Identify affected devices and owners.
  • Verify gNPSI enablement and exposure.
  • Plan configuration changes or vendor updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Arista EOS and the gNPSI feature?

Arista EOS is the operating system powering Arista's high-performance network switches used in data centers and cloud networks. The gRPC Network Packet Sampling Interface (gNPSI) is a specialized feature within EOS designed for streaming network traffic data. It allows administrators to export packet samples to external telemetry collectors for monitoring, visibility, and performance analysis.

What does CWE-94 mean for CVE-2026-73456?

CWE-94 refers to improper control of generation of code, often called code injection. In the context of CVE-2026-73456, this means the gNPSI interface fails to properly sanitize or validate incoming network requests. Consequently, an attacker can supply malicious instructions that the switch interprets and runs as legitimate code, granting them control over the device's operating system.

How is this vulnerability triggered?

An attacker triggers this vulnerability by sending a specially crafted, unauthenticated gRPC request directly to the gNPSI interface on an affected switch. The vulnerability does not trigger if the gNPSI feature is disabled. Furthermore, it requires network connectivity to the specific interface, meaning internal components or devices that do not have gNPSI turned on are not susceptible.

Do I need to worry if my switches are internal?

According to Halo Surface Signal, this vulnerability is considered 'Unlikely' to be exploited from the public internet because gNPSI is typically used for internal telemetry. However, because it allows for full administrative control, you should still care if the switch is reachable by any compromised or untrusted device within your internal network, as the interface does not require authentication.

When should I take action for CVE-2026-73456?

You should prioritize this immediately if your infrastructure relies on Arista EOS. Begin by auditing your network environment to identify which switches have the gNPSI feature enabled. Once you have a list of active configurations, coordinate with your network engineering team to restrict access to this interface or apply vendor-recommended configuration changes to mitigate the risk of unauthorized administrative access.

References