Impact
The vulnerability exists in Arista EOS’s gRPC Network Security Interface (gNSI) Credentialz service. A specially crafted request can modify properties of a target account, potentially granting the account elevated privileges or access beyond those intended by an administrator. This flaw leads to privilege escalation and could compromise confidentiality and integrity of systems if an attacker can manipulate account permissions.
Affected Systems
The issue affects Arista Networks EOS running any version where the gNSI Credentialz service is enabled. The vendor lists affected releases as the current versions of the 4.33.x, 4.34.x, 4.35.x, and 4.36.x trains: 4.33.9M and later, 4.34.7.1M and later, 4.35.6M and later, and 4.36.1F and later. Older releases prior to these, if running gNSI Credentialz, remain vulnerable. The service is not enabled by default, so the risk is higher for environments where administrators enable Credentialz for service automation.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. The EPSS score of less than 1% suggests exploitation is unlikely in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector requires an attacker to reach the EOS device’s management interface and send a crafted gNSI Credentialz request. Because the service is not enabled by default, this attack is principally an internal threat, requiring either privileged access to the device or the ability to configure the service. In environments where Credentialz is enabled, an attacker could compromise account privileges and execute unauthorized actions.
OpenCVE Enrichment