Vulnerabilidad · Publicado 16/09/2026
Plataformas Arista EOS con OpenConfig y servidor gNMI configurados pueden fallar en la validación de políticas gNSI Pathz cuando existen reglas simultáneas de grupo y usuario para la misma ruta, permitiendo que usuarios autenticados eludan restricciones de acceso. Esta vulnerabilidad afecta directamente a infraestructuras de red en centros de datos y proveedores de servicios en LATAM que dependen de estos controles de seguridad para gestionar acceso remoto.
On affected platforms running Arista EOS, if OpenConfig is configured and running a gNMI server on the system, and if gNSI Pathz is configured and a gNSI Pathz policy is present on the system, then gNMI may fail to correctly enforce the rules in this policy if both a group rule and a user rule for the same path is present in the policy. Under certain conditions, this can lead to an authenticated user gaining unauthorized permission to read or write gNMI paths that the Pathz policy is intended to restrict.
Score: 7.5/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-842
Publicado en NIST NVD.