Database/Firmware, BMC & network fabric

Arista EOS: gNMI fails to enforce Pathz policy when a group rule and a user rule cover the same path
Impact
When OpenConfig gNMI is running and a gNSI Pathz authorization policy contains both a group rule and a user rule for the same path, EOS may resolve them incorrectly and let an authenticated user read or write gNMI paths the policy was written to deny. The practical effect is that the delegation model an operator built for a shared fabric does not hold: a restricted automation account or a limited operator can read configuration and state it should not see, or push changes to it. On a GPU cluster the affected switches carry storage and east-west traffic for multiple tenants, so unauthorized write access to interface, ACL or routing paths reaches beyond the account's own scope.
Who can reach it
An authenticated gNMI client on the management network whose access is supposed to be constrained by a Pathz policy. Exploitation requires the specific policy shape - a group rule and a user rule for the same path - so it depends on how the policy was authored.
What to do
Follow Arista security advisory 0164: upgrade EOS to the fixed release for your platform. As an interim step, audit Pathz policies for paths covered by both a group rule and a user rule and rewrite them so the intended restriction is expressed by a single rule type, or disable the gNMI server until patched. EOS upgrade requires a switch reload on most platforms; the advisory does not describe a hot patch, so schedule per-switch maintenance with redundant paths available.
References
Related entries
- Intel DCI (Direct Connect Interface) UEFI setting restrictions - Xeon E3 v5/v6, Xeon Scalable, Xeon D: The UEFI settingCVE-2018-3652 · Intel DCI (Direct Connect Interface) UEFI setting restrictions - Xeon E3 v5/v6, Xeon Scalable, Xeon DHigh
- AMI MegaRAC SPx (BMC cryptography / HMAC): The BMC uses inadequate HMAC strength, so an attacker positionedCVE-2023-34337 · AMI MegaRAC SPx (BMC cryptography / HMAC)High
- Dell iDRAC9 (IPMI 2.0 over LAN): iDRAC9 generates predictable IPMI 2.0 session IDs, so an attacker can hijack somebodyCVE-2024-25943 · Dell iDRAC9 (IPMI 2.0 over LAN)High
- IBM Power Systems Firmware: unauthenticated ASMI web request crashes the service-processor interfaceCVE-2026-16828 · IBM Power Systems Firmware ASMI web interfaceHigh
- Opengear console server: Authentication bypass in the console server allowing remote attackers to modify settingsCVE-2011-3997 · Opengear console serverHigh
- Supermicro IPMI BMC firmware - hardcoded WSMAN credentials (X9 before SMT_X9_315, X8 before SMT X8 312): The BMCCVE-2013-3620 · Supermicro IPMI BMC firmware - hardcoded WSMAN credentials (X9 before SMT_X9_315, X8 before SMT X8 312)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.