Database/Firmware, BMC & network fabric

Arista EOS: crafted gNSI Credentialz request can grant an account privileges beyond what was configured
Impact
On EOS switches with the gNSI Credentialz service configured, a specially crafted request can modify properties of a target account, including assigning it privileges an administrator never granted. Arista rates this 8.6 with a low-privilege network vector, so a holder of any authenticated credential on the management plane can escalate to broader switch control. On a GPU fabric that means the leaf/spine carrying cross-tenant east-west traffic can be reconfigured: VLAN and ACL changes, mirroring of tenant traffic, or persistence on a device that is rarely reimaged. Switch compromise is felt by every node behind it, not just one tenant.
Who can reach it
Any account that can authenticate to the switch management plane and reach the gNSI/gRPC endpoint. Authentication is required, but only low privilege. Platforms without gNSI Credentialz configured are not affected.
What to do
Follow Arista security advisory 0165: upgrade EOS to a fixed release, or apply the advisory's mitigation of disabling or restricting the gNSI Credentialz service if the fixed train is not yet qualified. Upgrading EOS means a switch reload unless the platform and release support a hitless upgrade path, so plan per-switch maintenance with the fabric in a redundant state; the advisory does not list a hot fix that avoids the reload. Confirm the fixed version for your platform in the advisory before scheduling.
References
Related entries
- InfiniBand / RoCEv2 transport - RNIC connection state (QP number, PSN) on Mellanox ConnectX-class and compatible RNICsNCVD-2021-003-infiniband-rocev2-transport-rnic · InfiniBand / RoCEv2 transport - RNIC connection state (QP number, PSN) on Mellanox ConnectX-class and compatible RNICsHigh
- InfiniBand / RoCEv2 transport - RNIC connection state (QP number, PSN) on Mellanox ConnectX-class and compatible RNICsNCVD-2021-009-infiniband-rocev2-transport-rnic · InfiniBand / RoCEv2 transport - RNIC connection state (QP number, PSN) on Mellanox ConnectX-class and compatible RNICsHigh
- NVMe-over-Fabrics protocol over RDMA - SPDK NVMe-oF target and Linux kernel nvmet: NeVerMore implemented seven attacksNCVD-2022-002-nvme-over-fabrics-protocol-over · NVMe-over-Fabrics protocol over RDMA - SPDK NVMe-oF target and Linux kernel nvmetHigh
- Alias Checking Trusted Module (ACTM) firmware for Intel Xeon processors, including Xeon 6: Improper access controlCVE-2026-20898 · Alias Checking Trusted Module (ACTM) firmware for Intel Xeon processors, including Xeon 6High
- Intel Ethernet Adapter manageability firmware (access control): Improper access control in Intel Ethernet adapterCVE-2021-33162 · Intel Ethernet Adapter manageability firmware (access control)High
- Crypto API Toolkit for Intel SGX: Improper access control in the SGX Crypto API Toolkit lets an authenticated userCVE-2022-21163 · Crypto API Toolkit for Intel SGXHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.