Database/Firmware, BMC & network fabric

Arista EOS gNSI Certz: crafted Rotate request runs arbitrary OS commands as root
Impact
An already-authenticated user of the gNSI Certz service can escalate to root command execution and fully compromise the switch. Certz is the certificate rotation interface, so the accounts that reach it are automation identities held by provisioning and PKI tooling - credentials that tend to be shared fleet-wide rather than per-switch. One compromised automation credential therefore converts into root on every switch that trusts it, including the fabric switches between tenants. The Bootz provisioning service is affected by the same issue.
Who can reach it
An authenticated client with access to the gNSI Certz (or Bootz) service, reachable over the network on the management plane. Requires high privileges per the vendor's vector, but that is the level automation accounts normally hold.
What to do
Restrict gNSI Certz and Bootz reachability to the provisioning hosts that need it and audit which identities hold that access. Apply the fixed EOS release or hotfix listed in Arista security advisory 0162 on a per-switch maintenance window; the record does not name a fixed version.
References
Related entries
- Arista EOS: gRPC OpenConfig requests authorized at the wrong privilege levelCVE-2026-73461 · Arista EOS (AAA authorization for gRPC/OpenConfig)Critical
- Arista EOS (redundant supervisor, RPR/SSO): On modular chassis with dual supervisors running RPR or SSO redundancyCVE-2023-24509 · Arista EOS (redundant supervisor, RPR/SSO)Critical
- Software House iSTAR Ultra firmware verification and web application (tested through 6.9.2): The controller verifiesCVE-2025-53696 · Software House iSTAR Ultra firmware verification and web application (tested through 6.9.2)Critical
- Phala dcap-qvl - the Rust/npm/Python DCAP quote verification library used to verify Intel SGX and TDX attestationCVE-2026-22696 · Phala dcap-qvl - the Rust/npm/Python DCAP quote verification library used to verify Intel SGX and TDX attestation…Critical
- Voltronic Power SNMP Web Pro: unauthenticated firmware upload yields root on the UPS management cardCVE-2026-44402 · Voltronic Power SNMP Web Pro 1.1 (upload.cgi firmware update endpoint)Critical
- fakefish: KubeVirt backend ignores Redfish credentials, exposing VM power and virtual mediaCVE-2026-71566 · fakefish (Redfish BMC shim, KubeVirt backend)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.