Database/Firmware, BMC & network fabric

Arista DANZ Monitoring Fabric: crafted file in an upgrade ISO bypasses image signature validation
Impact
The cryptographic check that is supposed to prove an upgrade image came from the vendor can be defeated by planting a specific file inside the upgrade ISO, so an operator who installs a tampered image gets code the vendor never signed. DANZ Monitoring Fabric sits on the tap and packet-broker path of the datacenter network, which means it sees traffic from across the fabric, including traffic that crosses tenant boundaries; persistent unsigned code there is a durable, well-positioned foothold. The record scores it as a scope change with integrity impact only - the attacker has to already be a low-privileged local user with access to the upgrade media, and an operator has to run the install. This is an insider or supply-path problem, not something reachable from the network.
Who can reach it
Local user with low privileges who can modify the upgrade ISO before installation, plus an operator who then performs the upgrade. Not reachable remotely.
What to do
Apply the DMF release Arista names in advisory 0124 - the record does not quote a fixed version, so take it from that advisory - which means a controller and fabric software upgrade with the usual DMF maintenance window. Until then, the practical control is the media path: fetch upgrade ISOs only from Arista, verify hashes out of band yourself, and restrict who can place files on the staging location the upgrade reads from.
References
Related entries
- Linux kernel (drivers/vfio/pci/mlx5): Migration and dirty-tracking state flags for an mlx5 VF were packed into sharedCVE-2026-64472 · Linux kernel (drivers/vfio/pci/mlx5)Medium
- TPM 2.0: timing side channel in RSA OAEP decryption can expose TPM-managed key material and forge attestationsCVE-2026-6727 · TPM 2.0 reference implementation (RSA OAEP decryption timing)Medium
- Arista EOS: RADIUS proxy suppresses CoA and Disconnect-Requests for local 802.1X sessionsCVE-2026-73449 · Arista EOS (RADIUS proxy with dynamic authorization / 802.1X CoA)Medium
- Arista EOS (security ACL vs NAT rule interaction): A security ACL drop rule is bypassed when a NAT ACL permit ruleCVE-2021-28511 · Arista EOS (security ACL vs NAT rule interaction)Medium
- AMI MegaRAC SPx 12 (BMC default TLS certificate): The BMC ships with a hard-coded default TLS certificate, so HTTPSCVE-2021-4228 · AMI MegaRAC SPx 12 (BMC default TLS certificate)Medium
- AMI MegaRAC SPx 12 / SPx 13 (BMC web session management): Session fixation combined with sessions that never properlyCVE-2021-46279 · AMI MegaRAC SPx 12 / SPx 13 (BMC web session management)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.