Impact
The vulnerability resides in the gNSI Credentialz service of Arista EOS. A crafted request can alter a target account's properties, granting it elevated privileges or unintended access. This may compromise confidentiality, integrity, and availability of the system, enabling attackers to perform further malicious actions.
Affected Systems
The affected product is Arista Networks EOS. Versions impacted include all releases in the 4.33.x train prior to 4.33.9M, the 4.34.x train prior to 4.34.7.1M, the 4.35.x train prior to 4.35.6M, and the 4.36.x train prior to 4.36.1F, as identified by the vendor.
Risk and Exploitability
The CVSS score of 8.6 reflects high severity. The EPSS score is below 1%, indicating a very low probability of exploitation in the wild, and the vulnerability is not currently listed in CISA KEV. Based on the description, the likely attack vector involves an attacker delivering a malicious gNSI request over the management network; the exploit requires the gNSI Credentialz service to be enabled.
OpenCVE Enrichment