Database/Firmware, BMC & network fabric

Arista EOS: crafted packet terminates the MACsec process and disrupts dataplane traffic
Impact
On Arista EOS platforms with MACsec configured, a specially crafted packet makes the MACsec process terminate; sustained delivery of such packets causes longer-term dataplane disruption. MACsec is what encrypts datacenter interconnect and leaf-spine links, including the links carrying storage and east-west training traffic between GPU halls. Losing the dataplane on those links stalls distributed training jobs and can fail collective operations across the whole allocation, and a repeated crash keeps the link down rather than flapping once. No code execution or data disclosure is claimed - this is availability only, scoped to adjacent-network reach.
Who can reach it
Adjacent network - an attacker who can put packets onto a link terminating on an affected EOS switch with MACsec configured. No authentication required.
What to do
Apply the EOS version or hotfix listed in Arista security advisory 0132. Arista publishes hitless hotfix patches for many such issues; where only a full EOS upgrade applies, the switch reloads, so plan it per-switch against your fabric redundancy - on a non-redundant spine that is a fabric maintenance window. Only platforms with MACsec configured are exposed, so confirm your configuration before scheduling.
References
Related entries
- Arista EOS: VRRPv2 IP-AH authentication bypass lets an attacker claim the virtual router master roleCVE-2026-73444 · Arista EOS VRRPv2 IP Authentication Header (IP-AH) authenticationMedium
- RDMA fabric + remote DRAM bank contention (cross-node covert channel): Bankrupt establishes a 74 Kb/s covert channelNCVD-2020-002-rdma-fabric-remote-dram-bank-con · RDMA fabric + remote DRAM bank contention (cross-node covert channel)Medium
- RDMA fabric + remote DRAM bank contention (cross-node covert channel): Bankrupt establishes a 74 Kb/s covert channelNCVD-2020-004-rdma-fabric-remote-dram-bank-con · RDMA fabric + remote DRAM bank contention (cross-node covert channel)Medium
- AMD Secure Processor TEE - Secure OS stack overrun (AMD-SB-3003): A stack overrun in the ASP Secure OS trustedCVE-2021-46746 · AMD Secure Processor TEE - Secure OS stack overrun (AMD-SB-3003)Medium
- Intel Server OpenBMC firmware (before egs-1.09) - authentication logic: An authenticated low-privilege user escalatesCVE-2023-31189 · Intel Server OpenBMC firmware (before egs-1.09) - authentication logicMedium
- Cisco NX-OS (bootloader / image signature verification): Secure boot on the switch is defeatable: an attackerCVE-2024-20397 · Cisco NX-OS (bootloader / image signature verification)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.