Database/Firmware, BMC & network fabric

Arista EOS (redundant supervisor, RPR/SSO): On modular chassis with dual supervisors running RPR or SSO redundancy
Impact
On modular chassis with dual supervisors running RPR or SSO redundancy, an existing unprivileged user can log in to the standby supervisor as root. The standby has full access to the chassis state and becomes the active supervisor on failover, so this is a straight unprivileged-to-root path on your largest, most central switches — typically the spines.
Who can reach it
Authenticated but unprivileged user with network access to the standby supervisor.
What to do
EOS upgrade. Requires a reload of the supervisors — do the standby first, fail over, then the former active, which keeps the chassis forwarding throughout. Until patched, restrict management reachability to the standby supervisor's address.
References
Related entries
- Software House iSTAR Ultra firmware verification and web application (tested through 6.9.2): The controller verifiesCVE-2025-53696 · Software House iSTAR Ultra firmware verification and web application (tested through 6.9.2)Critical
- Riello NetMan 204: unauthenticated admin pages allow UPS shutdown and config disclosureCVE-2025-71318 · Riello UPS NetMan 204 network management card (admin pages and command endpoints)Critical
- Phala dcap-qvl - the Rust/npm/Python DCAP quote verification library used to verify Intel SGX and TDX attestationCVE-2026-22696 · Phala dcap-qvl - the Rust/npm/Python DCAP quote verification library used to verify Intel SGX and TDX attestation…Critical
- Voltronic Power SNMP Web Pro: unauthenticated firmware upload yields root on the UPS management cardCVE-2026-44402 · Voltronic Power SNMP Web Pro 1.1 (upload.cgi firmware update endpoint)Critical
- fakefish: KubeVirt backend ignores Redfish credentials, exposing VM power and virtual mediaCVE-2026-71566 · fakefish (Redfish BMC shim, KubeVirt backend)Critical
- Linux kernel (drivers/infiniband/hw/bnxt_re): A user context could request the write-combine doorbell page repeatedlyCVE-2026-72495 · Linux kernel (drivers/infiniband/hw/bnxt_re)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.