Database/Firmware, BMC & network fabric

Arista EOS (security ACL vs NAT rule interaction): A security ACL drop rule is bypassed when a NAT ACL permit rule
Impact
A security ACL drop rule is bypassed when a NAT ACL permit rule matches the same packet. Traffic you explicitly denied is forwarded. Same class of problem as the VXLAN ACL bug — the enforcement does not match the config, so your segmentation audit passes while the boundary is open.
Who can reach it
Any source whose traffic matches both a NAT permit and a security deny. Requires NAT to be configured on the device, which is common on the cluster's egress or storage-gateway leaves.
What to do
EOS upgrade plus reload. Interim: avoid overlapping NAT and security ACL match spaces on the same device, and verify enforcement with actual traffic tests rather than reading the config. Live config change.
References
Related entries
- AMI MegaRAC SPx 12 (BMC default TLS certificate): The BMC ships with a hard-coded default TLS certificate, so HTTPSCVE-2021-4228 · AMI MegaRAC SPx 12 (BMC default TLS certificate)Medium
- AMI MegaRAC SPx 12 / SPx 13 (BMC web session management): Session fixation combined with sessions that never properlyCVE-2021-46279 · AMI MegaRAC SPx 12 / SPx 13 (BMC web session management)Medium
- Tyan S5552 BMC web interface, firmware version 3.00: An unauthenticated attacker downloads the BMC's TLS private keyCVE-2023-2538 · Tyan S5552 BMC web interface, firmware version 3.00Medium
- Dell iDRAC Service Module (out-of-bounds write): Out-of-bounds write allowing a privileged local attacker to executeCVE-2024-38490 · Dell iDRAC Service Module (out-of-bounds write)Medium
- EDK2: BIOS exposes sensitive information to a local unauthorized actorCVE-2024-38798 · TianoCore EDK2 (BIOS)Medium
- Arista EOS (PBR / BGP Flowspec / interface traffic policy): IPv4 packets carrying IP options can bypass policy-basedCVE-2024-6437 · Arista EOS (PBR / BGP Flowspec / interface traffic policy)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.