Horizon Alert
Summary of the vulnerability and why it matters
This vulnerability affects network platforms that use gRPC authorization for configuration requests. When improperly configured, authenticated users may be granted unintended access levels through a specific authorization method, though it does not impact other configuration methods like NETCONF. The primary concern is confirming if the affected configuration is in use within your environment.
- Misconfigured authorization on network devices.
- Potential for unintended access to network configurations.
- Confirm relevance and exposure within your network.
Attack Path
How an attacker could exploit the issue
An attacker who has authenticated to an affected EOS platform could potentially leverage the vulnerability to gain elevated privileges. This occurs when gRPC requests for OpenConfig are processed with an incorrect authorization level due to a flaw in how privilege levels are handled, even though other OpenConfig requests are unaffected.
- Authenticated access required.
- gRPC OpenConfig requests trigger vulnerability.
- Potential for elevated privileges.
Live Threat
Current exploitation, exposure, and threat context
When AAA-based gRPC authorization is enabled for OpenConfig on affected EOS platforms, an authenticated user's gRPC requests may be processed with an incorrect privilege level. This could lead to the execution of actions beyond the user's intended access, impacting service behavior. This vulnerability does not affect other OpenConfig request types like NETCONF.
- Network device configurations.
- Incorrect AAA authorization.
- Unauthorized configuration changes.
Operational Fix
Recommended remediation, mitigation, and detection steps
The described vulnerability affects network platforms with AAA-based gRPC authorization for OpenConfig, indicating that infrastructure or network operations teams are likely responsible for remediation. The immediate first step should be to identify all affected devices, confirm their exposure and criticality, and then determine the appropriate ownership for planning the next actions.
- Infrastructure and network teams own the issue.
- Verify affected platforms and criticality.
- Plan remediation based on identified risk.