Database/Firmware, BMC & network fabric
Arista CVX: authenticated Redis session escalates to root on every server in the CVX cluster
Impact
An attacker who can reach the Redis service on a CVX server and holds the Redis password gets full root on all servers in the CVX cluster. CVX is the controller plane for the switch fabric, so root there means the ability to rewrite fabric state - VXLAN/VLAN mappings, MAC and ARP tables - that is shared across every tenant hanging off those switches. Arista notes that all Redis traffic, including authentication, is plaintext today, so the password can also be recovered by anyone able to observe management-network traffic. For a GPU cluster, compromise of the fabric controller is a cross-tenant event that no per-node hardening contains.
Who can reach it
Network access to the Redis port on a CVX server plus the Redis password. Authentication is required, but the credential travels in cleartext on the management network, so a passive observer on that VLAN can obtain it.
What to do
Upgrade CVX to the fixed release named in Arista advisory 0126 and restart the CVX service; the advisory does not list a hotfix in the record given here. Until then, restrict reachability of the Redis port to a trusted management segment and treat the Redis password as exposed - TLS for Redis is still an open feature request (RFE1294850). Cost is a controller-service restart rather than a compute-node maintenance window; GPU nodes do not need draining, but fabric programming pauses while CVX restarts.
References
Related entries
- AMI AptioV UEFI firmware: incomplete input validation lets a privileged local user execute code in firmware contextCVE-2026-33197 · AMI AptioV UEFI firmware (BIOS input validation)High
- Linux kernel mlx5_core eswitch / vport (SR-IOV): Mlx5_core sizes a firmware command buffer from the physical function'sCVE-2026-53230 · Linux kernel mlx5_core eswitch / vport (SR-IOV)High
- Arista EOS gNMI: crafted request from an authenticated client executes code as rootCVE-2026-73464 · Arista EOS (gNMI - gRPC Network Management Interface)High
- Cisco FXOS / NX-OS AAA: AAA implementation flaw enabling remote DoS via brute-force login attempts against the switchCVE-2017-3883 · Cisco FXOS / NX-OS AAAHigh
- Cisco NX-OS PTP feature (Nexus 5500/5600/6000): An unauthenticated remote attacker takes down a Nexus switch throughCVE-2018-0378 · Cisco NX-OS PTP feature (Nexus 5500/5600/6000)High
- Cisco NX-OS (VXLAN OAM / NGOAM): A crafted VXLAN OAM packet reloads a VTEP. In a VXLAN/EVPN GPU fabric every leaf is aCVE-2021-1587 · Cisco NX-OS (VXLAN OAM / NGOAM)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.