Database/Firmware, BMC & network fabric

Arista EOS (OpenConfig gNMI Set authorization): A gNMI Set request that authorization should have rejected is executed
Impact
A gNMI Set request that authorization should have rejected is executed, so a caller writes switch configuration it has no right to write. Model-driven management is how large fabrics are actually operated now, and gNMI is the write path — if its authorization does not hold, your RBAC on the fabric does not exist. Pairs with CVE-2024-27890 (same defect, separate advisory) and CVE-2025-1260 on the gNOI side.
Who can reach it
A client able to reach the gNMI endpoint with credentials whose authorization should have been insufficient. Requires OpenConfig to be configured.
What to do
EOS upgrade plus reload. Interim: restrict gNMI/gNOI reachability with a control-plane ACL to only the automation hosts that legitimately write config — live config change and worth doing permanently.
References
Related entries
- IBM Power FSP: malformed ASMI request gives unauthenticated code execution on the service processorCVE-2026-16687 · IBM Power Systems Firmware (FSP service processor, ASMI web interface)Critical
- IBM Power FSP: management protocol authentication bypass yields full administrative control of the hostCVE-2026-16835 · IBM Power Systems Firmware (FSP management network protocol authentication)Critical
- Arista EOS P4Runtime: unauthenticated client can gain full administrative control of the switchCVE-2026-73453 · Arista EOS (P4Runtime service)Critical
- Arista EOS gNSI Certz: crafted Rotate request runs arbitrary OS commands as rootCVE-2026-73447 · Arista EOS (gNSI Certz service, also Bootz)Critical
- Arista EOS: gRPC OpenConfig requests authorized at the wrong privilege levelCVE-2026-73461 · Arista EOS (AAA authorization for gRPC/OpenConfig)Critical
- Lantronix console servers: command injection in the NFS download CLI yields root on the out-of-band management deviceCVE-2026-80151 · Lantronix SLC8000/SLC9000/EMG console servers (CLI 'set nfs download' command)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.