Database/Firmware, BMC & network fabric

Arista EOS: spoofed dual-primary packets make the MLAG secondary err-disable its interfaces
Impact
An unauthenticated attacker on the dual-primary detection segment can inject packets that corrupt MLAG dual-primary state. If the MLAG primary then fails, the secondary wrongly concludes both peers are primary and err-disables its interfaces - so the failover that was supposed to keep the rack online instead takes the whole MLAG pair down. For a GPU fleet this is a rack-wide loss of north-south and storage connectivity, and err-disabled ports need operator action to recover, not just a link flap. It requires the attacker to be present at the moment of a primary failure, which is why the vector is rated attack-requirements-present.
Who can reach it
Unauthenticated attacker with packet access to the MLAG dual-primary detection network segment. This is normally a management or peer-link segment, so exposure depends on whether that segment is reachable from tenant or general-purpose networks.
What to do
Upgrade to the fixed EOS release or apply the hotfix from Arista security advisory 0161; the record does not name a fixed version, so take it from the advisory. Until then, restrict the dual-primary detection segment to the MLAG peers themselves. Upgrading an MLAG pair is a two-stage switch maintenance window and each stage removes one side of the redundancy.
References
Related entries
- Arista EOS: injected IS-IS LSP PDU purges a legitimate LSP from the link-state databaseCVE-2026-73459 · Arista EOS IS-IS (LSP PDU processing, link-state database)High
- Arista EOS: malformed IS-IS LSP PDU aborts graceful restart, causing traffic loss on restartCVE-2026-73460 · Arista EOS IS-IS graceful restart (malformed LSP PDU handling)High
- GRUB2 (USB device initialization): Out-of-bounds write in grub_usb_device_initialize from a malicious USB descriptorCVE-2020-25647 · GRUB2 (USB device initialization)Medium
- AMD Secure Processor PCI driver - input validation: Improper input validation in the ASP PCI driver lets a localCVE-2025-0045 · AMD Secure Processor PCI driver - input validationMedium
- AMD SEV firmware - RMP write during SNP initialization: A privileged attacker can write to the reverse map page duringCVE-2025-29939 · AMD SEV firmware - RMP write during SNP initializationMedium
- AMD Secure Processor PCI driver - use-after-free: A use-after-free reachable through the ASP PCI driverCVE-2025-48521 · AMD Secure Processor PCI driver - use-after-freeMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.