GPU VulnDB

Database/Firmware, BMC & network fabric

Arista CVX: authenticated Redis session escalates to root on every server in the CVX cluster

CVSS 8.7CVE-2025-5088Firmware, BMC & network fabriccurated

Impact

An attacker who can reach the Redis service on a CVX server and holds the Redis password gets full root on all servers in the CVX cluster. CVX is the controller plane for the switch fabric, so root there means the ability to rewrite fabric state - VXLAN/VLAN mappings, MAC and ARP tables - that is shared across every tenant hanging off those switches. Arista notes that all Redis traffic, including authentication, is plaintext today, so the password can also be recovered by anyone able to observe management-network traffic. For a GPU cluster, compromise of the fabric controller is a cross-tenant event that no per-node hardening contains.

Who can reach it

Network access to the Redis port on a CVX server plus the Redis password. Authentication is required, but the credential travels in cleartext on the management network, so a passive observer on that VLAN can obtain it.

What to do

Upgrade CVX to the fixed release named in Arista advisory 0126 and restart the CVX service; the advisory does not list a hotfix in the record given here. Until then, restrict reachability of the Redis port to a trusted management segment and treat the Redis password as exposed - TLS for Redis is still an open feature request (RFE1294850). Cost is a controller-service restart rather than a compute-node maintenance window; GPU nodes do not need draining, but fabric programming pauses while CVX restarts.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.