GPU VulnDB

Database/Firmware, BMC & network fabric

Arista EOS (L2 forwarding / VLAN isolation): TENANT ISOLATION: ingress traffic on a layer-2 port is forwarded out ports

CVE-2024-11185Firmware, BMC & network fabricArista Security Advisory 0118curated

Impact

TENANT ISOLATION: ingress traffic on a layer-2 port is forwarded out ports belonging to a different VLAN. VLAN separation is the primary tenant boundary in most GPU-cluster builds, so this is one tenant's frames landing in another tenant's broadcast domain. CVSS 6.5 understates the operator consequence — for a neocloud selling isolated tenancy this is a contractual failure, not a medium-severity bug.

Who can reach it

An attacker on any L2 port under the conditions the advisory describes. No credentials — this is a forwarding-plane defect, not an access-control one.

What to do

EOS upgrade plus switch reload on every affected leaf. No config workaround — you cannot ACL your way out of a forwarding-plane leak. Plan a rolling upgrade across the leaf layer; on MLAG pairs you can do one side at a time and keep the rack up.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.