Database/Firmware, BMC & network fabric

Arista EOS: gNSI Authz Rotate can activate the in-flight authorization policy
Impact
During a gNSI Authz Rotate RPC, a policy uploaded in the ongoing stream can become active even though it was not meant to be committed. The result is a switch enforcing an authorization policy the operator did not finalize - the command-authorization rules on a fabric device silently differ from what the management system believes it pushed. For an operator automating switch config across a GPU fabric with gNMI/gNSI, this breaks the assumption that a failed or abandoned rotate leaves the old policy in place. Bootz is not affected. Found internally by Arista, with no known exploitation.
Who can reach it
Requires high privilege on the management path (CVSS PR:H) - someone already authorized to drive gNSI RPCs against the switch, i.e. the automation system or an operator on the management network.
What to do
Apply the fix per Arista advisory 0167. Until then, verify the active Authz policy on each switch after any rotate operation rather than trusting the RPC's outcome, and treat gNSI access as the privileged path it is.
References
Related entries
- Arista EOS: loose uRPF fails to drop some traffic it should verifyCVE-2026-73469 · Arista EOS loose uRPF filteringMedium
- Insyde InsydeH2O on ARM platforms (HDD password storage in UEFI variables): HDD passwords are recoverable from UEFICVE-2026-8810 · Insyde InsydeH2O on ARM platforms (HDD password storage in UEFI variables)Medium
- Dell iDRAC (u-boot): Improper error handling grants access to the u-boot shell — pre-BMC-OS control, i.eCVE-2018-15776 · Dell iDRAC (u-boot)Medium
- Intel SSD DC S4500 and SSD DC S4600 series firmware before SCV10150 - improper authentication: Improper authenticationCVE-2018-18095 · Intel SSD DC S4500 and SSD DC S4600 series firmware before SCV10150 - improper authenticationMedium
- Intel Boot Guard in Intel CSME / TXE / SPS: Insecure default initialisation in Boot Guard means the S3 resume path doesCVE-2020-8705 · Intel Boot Guard in Intel CSME / TXE / SPSMedium
- Intel / Solidigm SSD, SSD DC and Optane SSD firmwareCVE-2021-33077 · Intel / Solidigm SSD, SSD DC and Optane SSD firmware - control-flow flaw and uncleared debug data reachable over…Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.