Database/Firmware, BMC & network fabric

Arista EOS: gNSI authz policy rotation can fail silently, leaving revoked gRPC access in place
Impact
On EOS switches with more than one gNSI transport configured, a race in the gNSI Authz service can make an authorization policy rotation fail without reporting an error. A user whose access the new policy was meant to revoke keeps working access to the switch's gRPC interfaces. For a datacenter spine/leaf or a fabric managed through gNMI/gNSI automation, that means an offboarded operator or a decommissioned automation credential still holds the ability to read or change switch configuration, and the management system believes otherwise. Integrity impact only per the CVSS vector; Bootz is not affected. Found internally by Arista, with no known exploitation reported.
Who can reach it
An authenticated gRPC/gNSI user whose privileges were supposed to be removed by a policy rotation. Requires reachability to the switch management gRPC endpoint - normally the management VLAN - and the switch must have multiple gNSI transports configured.
What to do
Apply the fixed EOS release or hotfix listed in Arista security advisory 0169. EOS patch rollout means a switch reload or (where an SSU/hotfix applies) a service restart, scheduled per device - on a single-homed fabric leg that is a maintenance window for the GPU nodes behind it. As an immediate check, re-verify effective authz policy after any rotation rather than trusting the rotation's result, and reduce to a single gNSI transport where the configuration allows it.
References
Related entries
- Arista EOS: private keys, user passwords and TACACS+ secrets logged in cleartext when debug tracing is onCVE-2026-73465 · Arista EOS logging (secrets written in cleartext under non-standard debug trace levels)Medium
- Infineon TPM firmware (RSA key generation): RSA keys generated inside affected Infineon TPMs are factorableCVE-2017-15361 · Infineon TPM firmware (RSA key generation)Medium
- STMicroelectronics ST33 TPM (ECDSA timing): Discrete TPM leaks ECDSA nonce data through timing, allowing private keyCVE-2019-16863 · STMicroelectronics ST33 TPM (ECDSA timing)Medium
- Arista EOS (EVPN VXLAN MAC/IP binding): Malformed packets create incorrect MAC-to-IP bindings in an EVPN VXLAN fabricCVE-2020-26569 · Arista EOS (EVPN VXLAN MAC/IP binding)Medium
- Arista EOS (802.1X on access/trunk ports): With 802.1X configured on access or trunk ports and routing enabled on theCVE-2023-5502 · Arista EOS (802.1X on access/trunk ports)Medium
- AMD SEV firmware - RMP protection bypass: An access-control failure in SEV firmware lets a malicious hypervisor bypassCVE-2025-29948 · AMD SEV firmware - RMP protection bypassMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.