Impact
This vulnerability allows an authenticated user to have gRPC requests processed with an incorrect privilege level, resulting in the use of an unintended AAA method list for authorization. Because the privilege level is misinterpreted, the attacker may execute privileged actions that would normally be restricted. The flaw does not affect NETCONF or non‑gRPC OpenConfig traffic, limiting the scope to only gRPC based sessions.
Affected Systems
Arista Networks EOS devices that have AAA-based gRPC authorization enabled for OpenConfig. Versions prior to the fix releases – 4.33.9M, 4.34.8M, 4.35.6M, and 4.36.1F – are affected. Devices running the listed releases or later are considered patched.
Risk and Exploitability
The flaw carries a CVSS score of 9.4 and is not yet listed in the CISA KEV catalog, though no EPSS data is available. An attacker would need authenticated access to the gRPC interface on the device. By sending crafted gRPC requests, the attacker can trigger the privilege‑level mismatch and thereby abuse higher‑level permissions, potentially compromising network control or configuration. Because the issue is limited to gRPC traffic and requires valid credentials, the likelihood of exploitation is moderate to high given the severity and the common use of gRPC in OpenConfig.
OpenCVE Enrichment