GPU VulnDB

Database/Firmware, BMC & network fabric

Arista CVX: unexpected messages from a connected switch crash CVX agents and destabilise the cluster

CVSS 7.1CVE-2025-5090Firmware, BMC & network fabriccurated

Impact

The CVX server does not handle unexpected messages from a connected switch, and the resulting agent crashes make the CVX cluster unstable. CVX is the control service the fabric leans on for shared state; losing it does not black-hole traffic by itself, but it takes away the coordination layer operators use to manage the fabric and can leave the cluster flapping until it is restored. Tracked separately from CVE-2025-5089, which also covers the reverse direction and the Sysdb agent crash on the switch itself - the affected side and the failure differ, so the two are listed on their own. Reaching this requires high-privilege access on a connected switch.

Who can reach it

An attacker with high-privilege access on a switch already connected to CVX, able to send custom TCP packets to the CVX server. Authenticated, from inside the fabric control path.

What to do

Upgrade the CVX server to a fixed version per Arista security advisory 0126 (fixed versions are in the advisory, not in the record here) and restart the CVX service; CVX runs as a service or VM, so this does not require touching the switches. A compromised or misbehaving switch is the precondition, so restricting switch administrative access limits exposure in the interim.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.