GPU VulnDB

Database/Firmware, BMC & network fabric

Arista DANZ Monitoring Fabric: debug API exposes config database contents including user password hashes

CVSS 4.3CVE-2025-54548Firmware, BMC & network fabriccurated

Impact

DANZ Monitoring Fabric is the controller for a packet-broker fabric that taps production datacenter links - in an AI fleet that is the fabric carrying tenant and storage traffic. A restricted DMF account can read portions of the configuration database through a debug API, including local user password hashes. Offline cracking of those hashes is the realistic path to a fabric administrator account, which would let an attacker reconfigure where traffic is mirrored. The record scopes this as limited confidentiality disclosure only; it does not describe any direct write access or code execution.

Who can reach it

Network access to the DMF controller's API with a valid but restricted (non-admin) account - so an operator or read-only user on the management VLAN, not an anonymous attacker.

What to do

Apply the fixed DMF release or the hotfix named in Arista security advisory 0124; the NVD record does not state the fixed version, so take it from the advisory. Remediation is a controller-side software update - expect a controller upgrade or hotfix install and a management-plane restart, not a switch-side flash. Until then, treat DMF local password hashes as exposed: rotate DMF account credentials and prune restricted accounts that do not need API access.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.