Impact
The flaw allows a malicious client that is already authenticated with the gRPC Network Management Interface (gNMI) to send a specially crafted request that bypasses input as root on the EOS operating system. The vulnerability is a classic code‑injection issue (CWE‑94). The potential impact is full control of the switch, which could be used to modify configuration, intercept traffic, or serve as a pivot for further attacks. The vulnerability description explicitly states this capability; further detail about the attacker’s abilities is inferred from the fact that root privileges are possible on EOS devices that have gNMI enabled and are running any release earlier than EOS 4.33.9M, 4.34.7.1M, 4.35.6M, or 4.36.1F. DMF‑managed EOS switches, which keep gNMI transports on by default, cannot apply the workaround of disabling gNMI until a firmware update is performed. The supplied advisory lists four specific train release ranges that contain the fix.
Affected Systems
Affected systems are Arista Networks EOS routers and switches that have the gRPC Network Management Interface (gNMI) enabled on releases preceding 4.33.9M of the 4.33.x train, 4.34.7.1M of the 4.34.x train, 4.35.6M of the 4.35.x train, or 4.36.1F of the 4.36.x train. Devices managed by DMF that keep gNMI enabled by default are also vulnerable because the workaround cannot be applied on those platforms.
Risk and Exploitability
The CVSS score of 8.7 classifies the vulnerability as high severity. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, suggesting that no large‑scale public exploit has been confirmed. The known attack path requires an authenticated gNMI client, implying that the threat is management host. Protecting gNMI credentials and limiting network reach to the gNMI services are essential controls.
OpenCVE Enrichment