Impact
The vulnerability allows a gNMI client to bypass security rules defined in a gNSI Pathz policy when both a group rule and a user rule reference the same path. Because the policy engine performs an incorrect comparison, the best‑matched rule is not applied and the request may be permitted. This flaw can enable an authenticated user to read or modify gNMI data that was supposed to be restricted, violating confidentiality and integrity of the device configuration and operational data.
Affected Systems
Arista Networks’ EOS operating system is affected. EOS versions older than 4.33.9M, 4.34.7M, 4.35.6M, and 4.36.1F contain the flaw. A system that has OpenConfig enabled, runs a gNMI server, and has at least one non‑empty gNSI Pathz policy in place is at risk.
Risk and Exploitability
The CVSS score of 7.7 reflects high severity. The EPSS score of less than 1% indicates that exploitation is currently unlikely, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, exploitation is straightforward for an attacker who can authenticate to the gNMI API and has knowledge of a policy that includes both group and user rules for the same path. The flaw requires no special privilege escalation beyond the existing gNMI session, making the attack path simple and the risk tangible when the conditions are met.
OpenCVE Enrichment