Impact
On Arista EOS platforms an authenticated user that accesses the gNMI service may permissions in excess of those they are configured for, allowing execution of commands or viewing of information beyond the user’s intended scope. The flaw is caused by an incorrect authorization decision implementation (CWE-863) and results in a potential elevation of privileges.
Affected Systems
Affected devices run Arista Networks EOS. Firmware versions prior to the following mitigations are vulnerable: 4.36.0F and earlier in the 4.36.x train, 4.35.5M and earlier in the 4.35.x train, 4.34.7M and earlier in the 4.34.x train, and 4.33.8M and earlier in the 4.33.x train. Upgrading to 4.36.1F or any later release in the 4.36.x train, 4.35.6M or later in the 4.35.x train, 4.34.8.34.x train, or 4.33.9M or later in the 4.33.x train resolves the issue.
Risk and Exploitability
The CVSS base score is 2.3, indicating low technical severity, and there is no EPSS data available. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access to gNMI, and the attacker must either control or be able to modify AAA authorization policies. Likely attack vectors include remote gNMI connections over the default port 6030 or other configured gNMI ports, using either mutual TLS or username/password authentication. Because the flaw yields incorrect privilege checks, recovery of the correct authorization state would require reapplying the correct policy after any change.
OpenCVE Enrichment