Database/Firmware, BMC & network fabric

Arista EOS (L2 forwarding / VLAN isolation): TENANT ISOLATION: ingress traffic on a layer-2 port is forwarded out ports
Impact
TENANT ISOLATION: ingress traffic on a layer-2 port is forwarded out ports belonging to a different VLAN. VLAN separation is the primary tenant boundary in most GPU-cluster builds, so this is one tenant's frames landing in another tenant's broadcast domain. CVSS 6.5 understates the operator consequence — for a neocloud selling isolated tenancy this is a contractual failure, not a medium-severity bug.
Who can reach it
An attacker on any L2 port under the conditions the advisory describes. No credentials — this is a forwarding-plane defect, not an access-control one.
What to do
EOS upgrade plus switch reload on every affected leaf. No config workaround — you cannot ACL your way out of a forwarding-plane leak. Plan a rolling upgrade across the leaf layer; on MLAG pairs you can do one side at a time and keep the rack up.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.