GPU VulnDB

Database/Firmware, BMC & network fabric

Arista DANZ Monitoring Fabric: crafted file in an upgrade ISO bypasses image signature validation

CVSS 5.9CVE-2025-54549Firmware, BMC & network fabriccurated

Impact

The cryptographic check that is supposed to prove an upgrade image came from the vendor can be defeated by planting a specific file inside the upgrade ISO, so an operator who installs a tampered image gets code the vendor never signed. DANZ Monitoring Fabric sits on the tap and packet-broker path of the datacenter network, which means it sees traffic from across the fabric, including traffic that crosses tenant boundaries; persistent unsigned code there is a durable, well-positioned foothold. The record scores it as a scope change with integrity impact only - the attacker has to already be a low-privileged local user with access to the upgrade media, and an operator has to run the install. This is an insider or supply-path problem, not something reachable from the network.

Who can reach it

Local user with low privileges who can modify the upgrade ISO before installation, plus an operator who then performs the upgrade. Not reachable remotely.

What to do

Apply the DMF release Arista names in advisory 0124 - the record does not quote a fixed version, so take it from that advisory - which means a controller and fabric software upgrade with the usual DMF maintenance window. Until then, the practical control is the media path: fetch upgrade ISOs only from Arista, verify hashes out of band yourself, and restrict who can place files on the staging location the upgrade reads from.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.