CVE-2025-1259

HIGH

Arista EOS 4.28.0-4.28.11, 4.29.0-4.29.8, 4.30.0-4.30.7, 4.31.0-4.31.4, 4.32.0-4.32.2, 4.33.0 - Improper Access Control

Title source: llm
STIX 2.1

Description

On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result in users retrieving data that should not have been available

Scores

CVSS v3 7.7
EPSS 0.0033
EPSS Percentile 24.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (6)
Arista Networks/EOS 4.28.0 - 4.28.12
Arista Networks/EOS 4.29.0 - 4.29.9
Arista Networks/EOS 4.30.0 - 4.30.8
Arista Networks/EOS 4.31.0 - 4.31.5
Arista Networks/EOS 4.32.0 - 4.32.3
Arista Networks/EOS 4.33.0 - 4.33.1
Published Mar 04, 2025
Tracked Since Feb 18, 2026