Database/Firmware, BMC & network fabric

Arista EOS: crafted packet brings down authenticated BFD sessions and triggers routing changes
Impact
A crafted packet drops configured BFD sessions even when they are authenticated, and because BGP, IS-IS and other protocols use BFD as their fast liveness signal, every protocol watching that session reacts as if the link failed. The result is unwanted reconvergence across the fabric from a single remotely reachable trigger - Arista scores this 9.2 with network attack vector and no privileges. For a GPU datacenter the underlay carries RoCE/InfiniBand-adjacent traffic and storage, and BFD is deliberately tuned aggressively there, so a forced session down means immediate rerouting or blackholing and dead distributed jobs. The fact that authentication does not protect the session is the important part: the usual mitigation is already in place and does not help.
Who can reach it
Unauthenticated, network-reachable: anyone who can get the crafted packet to a switch with BFD sessions configured. BFD authentication being enabled does not prevent it.
What to do
Upgrade to the fixed EOS release or apply the hotfix from Arista security advisory 0154; an EOS upgrade means a switch reload, so stage it rack by rack with workloads drained. Because BFD authentication is not a mitigation here, the interim options are limiting which peers can reach BFD-enabled interfaces with control-plane ACLs and, where the design tolerates it, relaxing protocol dependence on BFD. Version details are in Arista's advisory only.
References
Related entries
- MikroTik RouterOS: SSH username argument handling lets an unauthenticated client escalate policy privilegesCVE-2026-86060 · MikroTik RouterOS (SSH login helper, policy mask handling)Critical
- Tripp Lite PDUMH15AT / SU750XL PDU: The PDU accepts unauthenticated POST requests to its /Forms/ endpoints, which canCVE-2019-16261 · Tripp Lite PDUMH15AT / SU750XL PDUCritical
- IBM OpenPower firmware OP910/OP920 - OpenBMC IPMI credential handling: The original default BMC password kept workingCVE-2019-4169 · IBM OpenPower firmware OP910/OP920 - OpenBMC IPMI credential handlingCritical
- Lanner IAC-AST2500A BMC firmware: An authenticated BMC user escalates to root code execution on the controllerCVE-2021-26731 · Lanner IAC-AST2500A BMC firmwareCritical
- Arista EOS (gNOI): gNOI APIs bypass authentication, allowing an unauthenticated factory reset of the switchCVE-2021-28506 · Arista EOS (gNOI)Critical
- APC Smart-UPS SMT/SMC/SMX/SCL/SMTL series - firmware update signing: Firmware images are signed with a key that leakedCVE-2022-0715 · APC Smart-UPS SMT/SMC/SMX/SCL/SMTL series - firmware update signingCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.