Impact
On Arista EOS platforms, an authenticated user that accesses the gNMI service may obtain permissions beyond those they are configured for, allowing execution of commands or viewing of information beyond the user’s intended scope. The flaw is caused by an incorrect authorization decision implementation (CWE-863) and results in a potential elevation of privileges.
Affected Systems
Devices running Arista Networks EOS firmware versions prior to 4.36.1F in the 4.36.x train, 4.35.6M in the 4.35.x train, 4.34.8M in the 4.34.x train, or 4.33.9M in the 4.33.x train are vulnerable. Upgrading to any of these fixes resolves the issue.
Risk and Exploitability
The CVSS base score of 2.3 indicates only a low technical severity. The EPSS score of 0.00192 (below 1%) suggests an extremely low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access to gNMI and either control or the ability to modify AAA authorization policies. Likely attack vectors include remote gNMI connections over the default port 6030 or other configured gNMI ports, using either mutual TLS or username/password authentication. Because the flaw yields incorrect privilege checks, recovery of the correct authorization state would require reapplying the correct policy after any change.
OpenCVE Enrichment