Database/Firmware, BMC & network fabric

Arista EOS: ingress ACLs on shared SVIs stop enforcing after a secondary switch card event
Impact
On dual switch card chassis, restarting the secondary switch card forwarding agent or inserting a secondary card can silently stop ingress security ACLs on shared-mode SVIs from being applied. Packets that should be denied are permitted. The failure is silent: the configuration still shows the ACL, so an operator auditing config sees a tenant boundary that the hardware is no longer enforcing. On a multi-tenant GPU fleet this is the difference between a segmented management or storage VLAN and an open one. Arista found this internally and reports no known exploitation.
Who can reach it
No attacker action triggers the condition - it follows an operational event on the switch (card insertion or forwarding agent restart). Exploitation afterwards only requires sending traffic that the ACL was supposed to deny.
What to do
Upgrade to the fixed EOS release or hotfix from Arista security advisory 0151; the record does not state a version. Operationally, after any secondary switch card insertion or forwarding agent restart on an affected chassis, verify ACL counters on shared SVIs rather than trusting the running configuration.
References
Related entries
- Linux KVM - PV TLB shootdown leaks memory between guest processes: In a KVM guest with paravirtualised TLB enabled, oneCVE-2019-3016 · Linux KVM - PV TLB shootdown leaks memory between guest processesMedium
- APC Network Management Card 2 (AP9630/AP9631/AP9635) in Smart-UPS, Symmetra and Galaxy 3500: Stored/reflectedCVE-2021-22810 · APC Network Management Card 2 (AP9630/AP9631/AP9635) in Smart-UPS, Symmetra and Galaxy 3500Medium
- Arista EOS (TerminAttr / OpenConfig telemetry transport): The streaming-telemetry agent can leak MACsec keys over theCVE-2021-28509 · Arista EOS (TerminAttr / OpenConfig telemetry transport)Medium
- IBM OpenBMC OP910 web UI (phosphor-webui lineage): Stored/reflected script injection in the BMC web interfaceCVE-2021-38961 · IBM OpenBMC OP910 web UI (phosphor-webui lineage)Medium
- Intel 3rd/4th Gen Xeon with SGX or TDX (protection mechanism failure): A protection mechanism in 3rd and 4th generationCVE-2023-22655 · Intel 3rd/4th Gen Xeon with SGX or TDX (protection mechanism failure)Medium
- shim (mok.c mirror_one_esl): NULL pointer dereference while printing an error message stops the node from bootingCVE-2023-40546 · shim (mok.c mirror_one_esl)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.