Database/Firmware, BMC & network fabric

Arista EOS (802.1X on access/trunk ports): With 802.1X configured on access or trunk ports and routing enabled on the
Impact
With 802.1X configured on access or trunk ports and routing enabled on the access VLAN, a malicious supplicant can skip 802.1X authentication entirely. Port-based admission control is what stops an unauthorized machine being plugged into a rack and joining the fabric — this makes it optional. Companion issue CVE-2024-6858 does the same thing in multi-auth mode via a device in the fallback VLAN.
Who can reach it
A device physically connected to a switch port that has 802.1X configured. Colocation, shared cages, and contractor rack-and-stack are the realistic scenarios.
What to do
EOS upgrade plus reload. Do not rely on 802.1X alone as the tenant admission boundary; combine it with per-port VLAN pinning and MAC allowlisting (live config) so a bypassed supplicant still lands nowhere useful.
References
Related entries
- AMD SEV firmware - RMP protection bypass: An access-control failure in SEV firmware lets a malicious hypervisor bypassCVE-2025-29948 · AMD SEV firmware - RMP protection bypassMedium
- AMD SEV firmware - improper initialization corrupting RMP-covered memory: An initialization defect in SEV firmware letsCVE-2025-29952 · AMD SEV firmware - improper initialization corrupting RMP-covered memoryMedium
- GRUB2 TPM auto-unlock: forced rescue mode leaves the LUKS volume decrypted with the key still in memoryCVE-2025-4382 · GRUB2 with TPM-based LUKS auto-decryption (rescue mode key retention)Medium
- AMD Secure Processor firmware - MMIO routing lock (Zen 5): A missing lock check in ASP firmware on some Zen 5 partsCVE-2025-54510 · AMD Secure Processor firmware - MMIO routing lock (Zen 5)Medium
- Arista DANZ Monitoring Fabric: crafted file in an upgrade ISO bypasses image signature validationCVE-2025-54549 · Arista DANZ Monitoring Fabric (upgrade image validation)Medium
- Linux kernel (drivers/vfio/pci/mlx5): Migration and dirty-tracking state flags for an mlx5 VF were packed into sharedCVE-2026-64472 · Linux kernel (drivers/vfio/pci/mlx5)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.