CVE-2026-73456
Dans certaines circonstances, sur les plateformes concernées exécutant Arista EOS avec l’interface gRPC Network Packet Sampling Interface (gNPSI) activée, un client gNPSI non authentifié peut élaborer une requête malveillante permettant l’exécution de code arbitraire et donnant à un attaquant un contrôle administratif complet du commutateur compromis.
Score CVSS10.0 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HType de faiblesse (CWE)CWE-94
Articles liés
This product uses the NVD API but is not endorsed or certified by the NVD.
La description technique est notre traduction du texte original du NVD, en anglais.
