Horizon Alert
Summary of the vulnerability and why it matters
An unauthenticated client could execute arbitrary code on Arista switches running gRPC Network Packet Sampling Interface (gNPSI) if this feature is enabled, potentially leading to a complete compromise of the affected device.
- Malicious code could run on network switches.
- Attackers gain full administrative control of switches.
- Confirm relevance and assess exposure.
Attack Path
How an attacker could exploit the issue
An attacker could target a network device running Arista EOS with the gRPC Network Packet Sampling Interface (gNPSI) enabled. By sending a specially crafted, unauthenticated request to this interface, an attacker could potentially execute arbitrary code on the device, leading to complete administrative control.
- Network access to gNPSI is required.
- A malicious gNPSI request triggers the vulnerability.
- Full administrative control of the switch can be gained.
Live Threat
Current exploitation, exposure, and threat context
When Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) is enabled, an unauthenticated client could execute arbitrary code, potentially allowing an attacker full administrative control over the affected network switch.
- Network switch administrative control.
- Malicious gRPC request sent to gNPSI.
- Full compromise of network device.
Operational Fix
Recommended remediation, mitigation, and detection steps
To address this critical vulnerability, the platform or infrastructure team responsible for Arista network devices should take the lead, in coordination with the network security team. The first practical step is to identify all Arista devices running the affected software, confirm if gRPC Network Packet Sampling Interface (gNPSI) is enabled, and assess their network exposure and business criticality. This will help prioritize remediation efforts, which may involve configuration changes or vendor engagement.
- Identify affected devices and owners.
- Verify gNPSI enablement and exposure.
- Plan configuration changes or vendor updates.