Database/Firmware, BMC & network fabric

Arista EOS (MACsec with egress ACLs): On interfaces with both MACsec and egress ACLs configured, the egress ACL is not
Impact
On interfaces with both MACsec and egress ACLs configured, the egress ACL is not enforced for packets leaving those ports. The combination — link encryption plus egress filtering — is exactly what you deploy on inter-site or inter-pod links carrying multiple tenants, so the failure lands on the highest-trust links in the build.
Who can reach it
Traffic egressing an interface configured with both MACsec and an egress ACL. No attacker capability needed.
What to do
EOS upgrade plus reload. Interim: move the filtering to the ingress direction on the far side of the link, which is a live config change and restores enforcement without touching MACsec.
References
Related entries
- Intel UEFI firmware (OutOfBandXML module): Improper initialisation in the OutOfBandXML UEFI module allows a privilegedCVE-2024-31157 · Intel UEFI firmware (OutOfBandXML module)Medium
- Dell PowerEdge 14G Intel BIOS (improper input validation): A high-privileged local attacker extracts informationCVE-2024-38303 · Dell PowerEdge 14G Intel BIOS (improper input validation)Medium
- Insyde InsydeH2O (IHISI function 0x49, UEFI variable factory reset): IHISI function 0x49 restores certain UEFICVE-2024-39707 · Insyde InsydeH2O (IHISI function 0x49, UEFI variable factory reset)Medium
- GRUB2 (HFS+ filesystem parser): A reference count can be decremented twice, producing a use-after-freeCVE-2024-45783 · GRUB2 (HFS+ filesystem parser)Medium
- AMD CPU - stale TLB entries in SEV-SNP guests: A silicon bug lets a local admin-privileged attacker run an SEV-SNPCVE-2025-29934 · AMD CPU - stale TLB entries in SEV-SNP guestsMedium
- Dell iDRAC Service Module (iSM, incorrect permissions): Incorrect permission assignment on a critical resource letsCVE-2025-38742 · Dell iDRAC Service Module (iSM, incorrect permissions)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.