Database/Firmware, BMC & network fabric

Arista EOS (OpenConfig gNOI authorization): The gNOI equivalent of the gNMI authorization bypass: operations
Impact
The gNOI equivalent of the gNMI authorization bypass: operations that should have been rejected run anyway. gNOI covers reboot, image install, certificate rotation and factory reset — so an under-privileged caller can reload switches or push images, not merely edit config.
Who can reach it
A client reaching the gNOI endpoint on a switch with OpenConfig configured, holding credentials that should not authorize the operation.
What to do
EOS upgrade plus reload. Immediately restrict gNOI endpoint reachability by ACL and re-issue any certificates that could have been rotated by an unauthorized caller.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.