Database/Firmware, BMC & network fabric

Arista DANZ Monitoring Fabric: debug API exposes config database contents including user password hashes
Impact
DANZ Monitoring Fabric is the controller for a packet-broker fabric that taps production datacenter links - in an AI fleet that is the fabric carrying tenant and storage traffic. A restricted DMF account can read portions of the configuration database through a debug API, including local user password hashes. Offline cracking of those hashes is the realistic path to a fabric administrator account, which would let an attacker reconfigure where traffic is mirrored. The record scopes this as limited confidentiality disclosure only; it does not describe any direct write access or code execution.
Who can reach it
Network access to the DMF controller's API with a valid but restricted (non-admin) account - so an operator or read-only user on the management VLAN, not an anonymous attacker.
What to do
Apply the fixed DMF release or the hotfix named in Arista security advisory 0124; the NVD record does not state the fixed version, so take it from the advisory. Remediation is a controller-side software update - expect a controller upgrade or hotfix install and a management-plane restart, not a switch-side flash. Until then, treat DMF local password hashes as exposed: rotate DMF account credentials and prune restricted accounts that do not need API access.
References
Related entries
- Self-encrypting drives in TCG Opal / eDrive modeCVE-2015-7267 · Self-encrypting drives in TCG Opal / eDrive mode - Samsung 850 Pro, Samsung PM851, Seagate ST500LT015, ST500LT025 on…Medium
- Samsung 840 EVO SSD - disk encryption key exposed through wear-levelled NAND and vendor-specific commands: The driveCVE-2018-12038 · Samsung 840 EVO SSD - disk encryption key exposed through wear-levelled NAND and vendor-specific commandsMedium
- Intel TDX module: The TDX module is the software that stands between the host/VMM and every confidential VM on the boxCVE-2025-20044 · Intel TDX moduleMedium
- Crucial/Micron MX100, MX200, MX300; Samsung 840 EVO and 850 EVO (ATA-high mode)CVE-2018-12037 · Crucial/Micron MX100, MX200, MX300; Samsung 840 EVO and 850 EVO (ATA-high mode); Samsung T3 and T5 portable SSDs…Medium
- AMD processors - speculative reordering of loads on shared memory: AMD processors may speculatively reorder loadCVE-2021-26400 · AMD processors - speculative reordering of loads on shared memoryMedium
- AMD SEV firmware - SEV-ES guest attacking an SNP guest: Coarse access-control granularity in SEV firmware lets aCVE-2025-48514 · AMD SEV firmware - SEV-ES guest attacking an SNP guestMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.