Database/Firmware, BMC & network fabric

Arista EOS gNMI: crafted request from an authenticated client executes code as root
Impact
An authenticated client with gNMI access can send a crafted request and execute arbitrary code with root privileges on the switch. gNMI is the standard streaming telemetry and configuration interface, so it is enabled on essentially every switch in an automated fabric and its credentials are held by monitoring and config-management systems. Compromise of any one of those systems therefore becomes root on the fabric switches that sit between tenants, with no further escalation step. Arista's vector rates the required privileges as low.
Who can reach it
An authenticated client with gNMI access over the network - in practice the telemetry collector or config-management identity. Applies to switches with gNMI enabled.
What to do
Limit gNMI reachability to the collectors and automation hosts that require it, and rotate the credentials those hosts hold if you suspect exposure. Apply the fixed EOS release or hotfix from Arista security advisory 0166 per switch; the record does not name a fixed version.
References
Related entries
- Cisco FXOS / NX-OS AAA: AAA implementation flaw enabling remote DoS via brute-force login attempts against the switchCVE-2017-3883 · Cisco FXOS / NX-OS AAAHigh
- Cisco NX-OS PTP feature (Nexus 5500/5600/6000): An unauthenticated remote attacker takes down a Nexus switch throughCVE-2018-0378 · Cisco NX-OS PTP feature (Nexus 5500/5600/6000)High
- Cisco NX-OS (VXLAN OAM / NGOAM): A crafted VXLAN OAM packet reloads a VTEP. In a VXLAN/EVPN GPU fabric every leaf is aCVE-2021-1587 · Cisco NX-OS (VXLAN OAM / NGOAM)High
- Intel Ethernet Adapter manageability firmware (NC-SI / sideband path): Improper input validation in the *manageability*CVE-2021-33141 · Intel Ethernet Adapter manageability firmware (NC-SI / sideband path)High
- GRUB2 (font engine, grub_font_construct_glyph): Buffer overflow when constructing a glyph from a crafted GRUB fontCVE-2022-2601 · GRUB2 (font engine, grub_font_construct_glyph)High
- Intel AMT / Standard Manageability firmware: Improper input validation in AMT/ISM firmware, scored high becauseCVE-2022-36392 · Intel AMT / Standard Manageability firmwareHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.