Back

CRITICAL

Security Advisory 0162 - gNSI Certz/Bootz OS Command Injection via Crafted Rotate Request

Published Sep 16, 2026

Description

A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full device compromise. An authenticated user can exploit gRPC Network Security Interface (gNSI) Certz service on Arista EOS-based products to escalate privileges and execute arbitrary OS commands via a crafted Certz Rotate request. The Bootz service is also affected.

Affected products

Remediation

Vendor solution

The following EOS releases contain the fix for this vulnerability: - 4.33.9M and later releases in the 4.33.x train - 4.34.7.1M and later releases in the 4.34.x train - 4.35.6M and later releases in the 4.35.x train - 4.36.1F and later releases in the 4.36.x train

No hotfix is available for this vulnerability.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Arista
Published Sep 16, 2026
Updated Sep 17, 2026
Reserved Aug 12, 2026
CISA Vulnrichment
Updated Sep 17, 2026
NVD
Status Awaiting Analysis
Modified Sep 17, 2026
Red Hat
Severity n/a
Public date n/a