GPU VulnDB

Database/Firmware, BMC & network fabric

Arista EOS (OpenConfig gNMI Set authorization): A gNMI Set request that authorization should have rejected is executed

CVE-2024-27892Firmware, BMC & network fabriccurated

Impact

A gNMI Set request that authorization should have rejected is executed, so a caller writes switch configuration it has no right to write. Model-driven management is how large fabrics are actually operated now, and gNMI is the write path — if its authorization does not hold, your RBAC on the fabric does not exist. Pairs with CVE-2024-27890 (same defect, separate advisory) and CVE-2025-1260 on the gNOI side.

Who can reach it

A client able to reach the gNMI endpoint with credentials whose authorization should have been insufficient. Requires OpenConfig to be configured.

What to do

EOS upgrade plus reload. Interim: restrict gNMI/gNOI reachability with a control-plane ACL to only the automation hosts that legitimately write config — live config change and worth doing permanently.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.