Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability exists in network devices that could allow a privileged attacker to execute arbitrary commands with full system control. This issue impacts specific administrative services, and while it requires existing access, successful exploitation could lead to a complete device compromise. The main concern is confirming relevance and exposure within our environment.
- Attackers could gain full control of affected devices.
- Leadership should remember this impacts critical network infrastructure.
- Confirm relevance and understand potential exposure.
Attack Path
How an attacker could exploit the issue
A privileged attacker with authenticated access can exploit a vulnerability in the Certz service, and potentially the Bootz service, of Arista EOS-based products. By sending a specially crafted request to the gRPC Network Security Interface (gNSI), the attacker can escalate their privileges and execute arbitrary operating system commands, leading to complete device compromise.
- Requires authenticated user access.
- Triggered by a crafted Certz Rotate request.
- Leads to full device compromise.
Live Threat
Current exploitation, exposure, and threat context
A privileged attacker with authenticated access could exploit the gRPC Network Security Interface (gNSI) Certz service, or the Bootz service, to execute arbitrary OS commands with root privileges. This could lead to a full device compromise when supported by the advisory's conditions.
- Root privileges and full device compromise.
- Authenticated users exploit gRPC services.
- Complete takeover of affected devices.
Operational Fix
Recommended remediation, mitigation, and detection steps
This critical vulnerability in Arista EOS products requires immediate attention from infrastructure and platform teams responsible for network device management. The first step is to inventory all Arista devices, identify those with the affected services exposed, and confirm their business criticality. Subsequently, engage the platform or network security teams to plan and execute remediation, coordinating with the vendor as needed.
- Own by Infrastructure/Platform teams.
- Verify gNSI/Bootz service exposure.
- Plan remediation with vendor coordination.