Impact
On Arista EOS systems that use multiple gNSI transports, the gNSI Authz service contains a race condition that can cause policy rotation to fail silently. When a new policy is applied, a user whose access has been revoked may still be able to use gRPC interfaces that should have been blocked. This issue does not impact Bootz. The vulnerability arises from improper handling of concurrent policy updates, leading to a race condition identified as CWE‑362. The consequence is that an authenticated user who had their privileges revoked can retain unauthorized access, which could be abused to perform unauthorized operations or reveal sensitive information.
Affected Systems
Affected products are Arista Networks Arista EOS. The issue is fixed in the following releases: EOS 4.36.1F and later of the 4.36.x train, 4.35.6M and later of the 4.35.x train, 4.34.7.1M and later of the 4.34.x train, 4.33.9M and later of the 4.33.x train. No hotfix is available. The vulnerability is not known to be actively exploited in the wild.
Risk and Exploitability
The CVSS score is 6, which classifies the severity as Medium. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers would need authenticated access to the gNSI transport and the ability to trigger a policy rotation. The race condition is likely exploitable in environments that enable multiple gNSI transports, but its impact is limited to retaining access after revocation, rather than offering remote code execution or full system compromise. Nevertheless, because it allows unauthorized use of gRPC interfaces, it can undermine the integrity and confidentiality of network management functions.
OpenCVE Enrichment