Database/Firmware, BMC & network fabric

Arista EOS: gRPC OpenConfig requests authorized at the wrong privilege level
Impact
With AAA-based gRPC authorization enabled for OpenConfig, an authenticated user's requests can be evaluated against the wrong AAA method list and the wrong privilege level. The practical result is that read-only or limited operator accounts may be permitted to perform configuration changes the authorization policy was written to deny - on the switches carrying the training fabric and storage network. Operators who rely on AAA tiering to let tooling or junior staff query switch state without changing it lose that separation silently, since the requests succeed rather than erroring. Non-gRPC OpenConfig paths such as NETCONF are not affected.
Who can reach it
Any authenticated user or automation identity that can issue gRPC OpenConfig requests to an affected switch with AAA-based gRPC authorization configured.
What to do
Treat gRPC OpenConfig access as effectively unrestricted until patched, and narrow which identities can reach it. Use NETCONF for OpenConfig access in the interim if that fits your tooling, since it is not affected. Take the fixed EOS release or hotfix from Arista security advisory 0163 and upgrade per switch; the record does not name a fixed version.
References
Related entries
- Arista EOS (redundant supervisor, RPR/SSO): On modular chassis with dual supervisors running RPR or SSO redundancyCVE-2023-24509 · Arista EOS (redundant supervisor, RPR/SSO)Critical
- Software House iSTAR Ultra firmware verification and web application (tested through 6.9.2): The controller verifiesCVE-2025-53696 · Software House iSTAR Ultra firmware verification and web application (tested through 6.9.2)Critical
- Phala dcap-qvl - the Rust/npm/Python DCAP quote verification library used to verify Intel SGX and TDX attestationCVE-2026-22696 · Phala dcap-qvl - the Rust/npm/Python DCAP quote verification library used to verify Intel SGX and TDX attestation…Critical
- Voltronic Power SNMP Web Pro: unauthenticated firmware upload yields root on the UPS management cardCVE-2026-44402 · Voltronic Power SNMP Web Pro 1.1 (upload.cgi firmware update endpoint)Critical
- fakefish: KubeVirt backend ignores Redfish credentials, exposing VM power and virtual mediaCVE-2026-71566 · fakefish (Redfish BMC shim, KubeVirt backend)Critical
- Linux kernel (drivers/infiniband/hw/bnxt_re): A user context could request the write-combine doorbell page repeatedlyCVE-2026-72495 · Linux kernel (drivers/infiniband/hw/bnxt_re)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.