Impact
An arbitrary code execution flaw exists in Arista EOS when gNPSI is enabled. An unauthenticated attacker can craft a malicious request that triggers execution of arbitrary code, giving full administrative control over the switch. The root weakness is identified as CWE-94, a command injection type flaw that compromises confidentiality, integrity and availability.
Affected Systems
Arista Networks EOS systems are vulnerable, specifically any EOS release that does not incorporate the 4.36.2F, 4.35.6M or 4.34.8M fixes and is running gNPSI. The advisory notes that the vulnerability affects all earlier releases of the 4.36.x, 4.35.x and 4.34.x train versions where gNPSI is active.
Risk and Exploitability
The CVSS score of 9.2 marks this as a critical issue, while the EPSS score of less than 1% indicates a low exploitation probability at present and it is not listed in the CISA KEV catalog. The attack vector relies on the gRPC interface provided by gNPSI, which is unauthenticated by default. Any host with network reach to the management interface can send the crafted request and immediately gain root access to the device.
OpenCVE Enrichment