Impact
The flaw in the gNSI Authz Rotate RPC allows an attacker to upload an incorrect authorization policy during an active RPC stream so that the policy becomes active. This can result in unintended privilege escalation, giving attackers elevated control over the device. The weakness is categorized as CWE‑20, reflecting an improper input validation issue that permits malformed policy data.
Affected Systems
Arista Networks EOS devices, affecting all releases older than 4.36.1F in the 4.36.x train, older than 4.35.6M in the 4.35.x train, older than 4.34.8M in the 4.34.x train, and older than 4.33.9M in the 4.33.x train.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. EPSS is unavailable, so the likelihood of exploitation is uncertain, and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be remote, via the gNSI Authz Rotate RPC accessed through the switch's gRPC interface. Successful exploitation would allow an attacker to replace the device’s authorization policy, effectively bypassing intended access controls.
OpenCVE Enrichment