GPU VulnDB

Database/Firmware, BMC & network fabric

Arista EOS: certain serial console input can cause an unexpected device reload

CVSS 5.6CVE-2025-8870Firmware, BMC & network fabriccurated

Impact

Specific input on the serial console can reload an affected Arista EOS switch. The impact is availability only - no disclosure, no code execution - but an unplanned reload of a datacenter switch drops every link on it, and on a GPU fabric that is enough to abort in-flight collectives on the racks behind it. Exposure is governed by who or what can type on the serial console: that is physical or serial-console-server access, which in a colocated or shared-cage deployment is a real population, and a console server reachable over the network widens it further. The advisory record is brief and does not describe the triggering input.

Who can reach it

Anyone able to send input to the device's serial console - physical access to the switch, or access to the serial console server or terminal concentrator it is wired into. No authentication to EOS is needed (vendor vector AV:P, PR:N).

What to do

Apply the fixed EOS release or hotfix named in Arista security advisory 0125. Arista ships many of these as hitless patches, so check the advisory for whether a reload is required before assuming a maintenance window. As a containment step independent of the fix, restrict who can reach the serial console: audit console-server access lists and cage access, since that is the only attack path.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.