Database/Firmware, BMC & network fabric

Arista EOS (L2 forwarding / VLAN isolation): Ingress traffic on a layer-2 port is forwarded out ports belonging to a
Impact
Ingress traffic on a layer-2 port is forwarded out ports belonging to a different VLAN. VLAN separation is the primary tenant boundary in most GPU-cluster builds, so this is one tenant's frames landing in another tenant's broadcast domain. CVSS 6.5 understates the operator consequence — for a neocloud selling isolated tenancy this is a contractual failure, not a medium-severity bug.
Who can reach it
An attacker on any L2 port under the conditions the advisory describes. No credentials — this is a forwarding-plane defect, not an access-control one.
What to do
EOS upgrade plus switch reload on every affected leaf. No config workaround — you cannot ACL your way out of a forwarding-plane leak. Plan a rolling upgrade across the leaf layer; on MLAG pairs you can do one side at a time and keep the rack up.
References
Related entries
- Redfish API implementation on Cisco UCS B-Series, UCS Managed C-Series and UCS X-Series servers: An administrator-levelCVE-2024-20365 · Redfish API implementation on Cisco UCS B-Series, UCS Managed C-Series and UCS X-Series serversMedium
- Intel Ethernet Controller E810 firmware: An unauthenticated attacker on the network can take an E810 NIC out of serviceCVE-2024-24983 · Intel Ethernet Controller E810 firmwareMedium
- SEV-ES / SEV-SNP guest kernel - unsolicited #VC (vector 29) injection: An untrusted hypervisor can inject the #VCCVE-2024-25742 · SEV-ES / SEV-SNP guest kernel - unsolicited #VC (vector 29) injectionMedium
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): Nothing orders the PTP send-queue tracking list againstCVE-2024-26858 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)Medium
- Intel processors with SGX (EDECCSSA leaf): Improper access control on the EDECCSSA user leaf function letsCVE-2024-36293 · Intel processors with SGX (EDECCSSA leaf)Medium
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en_accel): The IPsec offload worker does not check the xfrmCVE-2024-49953 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en_accel)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.