Database/Firmware, BMC & network fabric

Arista EOS: loose uRPF fails to drop some traffic it should verify
Impact
On specific platforms, traffic that a loose Unicast Reverse Path Forwarding configuration should drop is instead forwarded. The anti-spoofing control an operator configured is partially ineffective, so spoofed-source packets can cross a boundary the design assumed was closed. In a multi-tenant GPU cloud where uRPF is one of the controls keeping one tenant's traffic from impersonating another's addresses, the gap is an isolation gap rather than an outage. Arista found this internally and reports no known exploitation. The record does not say which traffic or which platforms, so confirm against the advisory for your hardware.
Who can reach it
Unauthenticated and network-reachable (AV:N) - any source able to send traffic through an interface relying on loose uRPF. No switch credentials needed.
What to do
Check Arista advisory 0176 for the affected platforms and fixed EOS releases before assuming your hardware is involved. Where uRPF is the only spoofing control on a boundary, add explicit ACL-based source filtering, which holds regardless of the EOS version, and schedule the upgrade normally rather than as an emergency.
References
Related entries
- Insyde InsydeH2O on ARM platforms (HDD password storage in UEFI variables): HDD passwords are recoverable from UEFICVE-2026-8810 · Insyde InsydeH2O on ARM platforms (HDD password storage in UEFI variables)Medium
- Dell iDRAC (u-boot): Improper error handling grants access to the u-boot shell — pre-BMC-OS control, i.eCVE-2018-15776 · Dell iDRAC (u-boot)Medium
- Intel SSD DC S4500 and SSD DC S4600 series firmware before SCV10150 - improper authentication: Improper authenticationCVE-2018-18095 · Intel SSD DC S4500 and SSD DC S4600 series firmware before SCV10150 - improper authenticationMedium
- Intel Boot Guard in Intel CSME / TXE / SPS: Insecure default initialisation in Boot Guard means the S3 resume path doesCVE-2020-8705 · Intel Boot Guard in Intel CSME / TXE / SPSMedium
- Intel / Solidigm SSD, SSD DC and Optane SSD firmwareCVE-2021-33077 · Intel / Solidigm SSD, SSD DC and Optane SSD firmware - control-flow flaw and uncleared debug data reachable over…Medium
- Intel Boot Guard and Intel TXT (hardware debug / INIT): Hardware debug modes and processor INIT handling can overrideCVE-2022-0004 · Intel Boot Guard and Intel TXT (hardware debug / INIT)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.