Database/Firmware, BMC & network fabric

Arista EOS gNPSI: unauthenticated request yields arbitrary code execution on the switch
Impact
A crafted gNPSI request from an unauthenticated client gives arbitrary code execution and full administrative control of the switch. gNPSI is a telemetry streaming interface, so it is typically enabled on exactly the switches an operator instruments most heavily - the fabric carrying training traffic. Control of a leaf or spine lets an attacker observe or divert traffic that crosses tenant boundaries and pivot into the management network. Only switches with gNPSI enabled are affected.
Who can reach it
Anyone who can reach the gNPSI endpoint on an affected switch, typically from the management or telemetry VLAN. No authentication required.
What to do
Disable gNPSI where it is not consumed, and restrict reachability of the telemetry endpoint to the collectors that need it. For switches that must keep it, take the fixed EOS release or hotfix from Arista security advisory 0158 and schedule a per-switch upgrade; the record does not name a fixed version.
References
Related entries
- Arista EOS: crafted packet brings down authenticated BFD sessions and triggers routing changesCVE-2026-73458 · Arista EOS BFD (authenticated session packet handling)Critical
- MikroTik RouterOS: SSH username argument handling lets an unauthenticated client escalate policy privilegesCVE-2026-86060 · MikroTik RouterOS (SSH login helper, policy mask handling)Critical
- Tripp Lite PDUMH15AT / SU750XL PDU: The PDU accepts unauthenticated POST requests to its /Forms/ endpoints, which canCVE-2019-16261 · Tripp Lite PDUMH15AT / SU750XL PDUCritical
- IBM OpenPower firmware OP910/OP920 - OpenBMC IPMI credential handling: The original default BMC password kept workingCVE-2019-4169 · IBM OpenPower firmware OP910/OP920 - OpenBMC IPMI credential handlingCritical
- Lanner IAC-AST2500A BMC firmware: An authenticated BMC user escalates to root code execution on the controllerCVE-2021-26731 · Lanner IAC-AST2500A BMC firmwareCritical
- Arista EOS (gNOI): gNOI APIs bypass authentication, allowing an unauthenticated factory reset of the switchCVE-2021-28506 · Arista EOS (gNOI)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.