GPU VulnDB

Database/Firmware, BMC & network fabric

Arista EOS (OpenConfig gNOI authorization): The gNOI equivalent of the gNMI authorization bypass: operations

CVE-2025-1260Firmware, BMC & network fabricArista Security Advisory 21098curated

Impact

The gNOI equivalent of the gNMI authorization bypass: operations that should have been rejected run anyway. gNOI covers reboot, image install, certificate rotation and factory reset — so an under-privileged caller can reload switches or push images, not merely edit config.

Who can reach it

A client reaching the gNOI endpoint on a switch with OpenConfig configured, holding credentials that should not authorize the operation.

What to do

EOS upgrade plus reload. Immediately restrict gNOI endpoint reachability by ACL and re-issue any certificates that could have been rotated by an unauthorized caller.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.