Database/Firmware, BMC & network fabric

Arista EOS (ingress ACL enforcement on ethernet/LAG): TENANT ISOLATION: with IPv4 ingress, MAC ingress, or IPv6
Impact
TENANT ISOLATION: with IPv4 ingress, MAC ingress, or IPv6 standard ingress ACLs applied to one or more ethernet or LAG interfaces, the policies may not be enforced at all. The third ACL-enforcement defect in the same family — worth treating Arista ingress ACLs as a control that needs periodic active verification rather than a set-and-forget boundary.
Who can reach it
Any traffic arriving on an affected interface. No attacker capability required.
What to do
EOS upgrade plus reload on affected platforms. Because ACL enforcement is the thing that fails, the only trustworthy verification is sending traffic that should be dropped and confirming it is — do that as a standing test in your fabric CI, not just after this patch.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.