Database/Firmware, BMC & network fabric

Arista EOS: VRRPv2 IP-AH authentication bypass lets an attacker claim the virtual router master role
Impact
VRRPv2 authentication using IP-AH can be bypassed, so an unauthenticated attacker on the VRRP layer 2 segment can take the master role for the virtual gateway address. Every host on that segment then sends its default-gateway traffic to the attacker, who can intercept, modify or drop it. Where a GPU cluster's storage, management or egress path runs through a VRRP gateway, this is a position on the wire for the whole segment, and it holds until the legitimate master is restored. The record's CVSS reflects availability only, but the description explicitly covers interception and modification.
Who can reach it
Unauthenticated attacker with access to the layer 2 segment on which VRRP runs. Any compromised host or tenant device on that VLAN qualifies; no switch credentials are needed.
What to do
Upgrade to the fixed EOS release or hotfix in Arista security advisory 0157 - the record does not name a fixed version. Treat IP-AH authentication as not providing the protection it appears to until patched, and keep VRRP segments off networks that untrusted hosts can reach. Rolling the fix means a switch maintenance window per gateway pair.
References
Related entries
- RDMA fabric + remote DRAM bank contention (cross-node covert channel): Bankrupt establishes a 74 Kb/s covert channelNCVD-2020-002-rdma-fabric-remote-dram-bank-con · RDMA fabric + remote DRAM bank contention (cross-node covert channel)Medium
- RDMA fabric + remote DRAM bank contention (cross-node covert channel): Bankrupt establishes a 74 Kb/s covert channelNCVD-2020-004-rdma-fabric-remote-dram-bank-con · RDMA fabric + remote DRAM bank contention (cross-node covert channel)Medium
- AMD Secure Processor TEE - Secure OS stack overrun (AMD-SB-3003): A stack overrun in the ASP Secure OS trustedCVE-2021-46746 · AMD Secure Processor TEE - Secure OS stack overrun (AMD-SB-3003)Medium
- Intel Server OpenBMC firmware (before egs-1.09) - authentication logic: An authenticated low-privilege user escalatesCVE-2023-31189 · Intel Server OpenBMC firmware (before egs-1.09) - authentication logicMedium
- Cisco NX-OS (bootloader / image signature verification): Secure boot on the switch is defeatable: an attackerCVE-2024-20397 · Cisco NX-OS (bootloader / image signature verification)Medium
- AMI AptioV UEFI BIOS (SPI flash integrity verification): An actor with physical access can modify the SPI flashCVE-2024-33660 · AMI AptioV UEFI BIOS (SPI flash integrity verification)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.