CVE-2025-1260: On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected.
On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result in unexpected configuration/operations being applied to the switch.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1260?
CVE-2025-1260 is classified as a high severity vulnerability that can lead to unexpected configuration changes on affected Arista EOS devices.
How do I fix CVE-2025-1260?
To resolve CVE-2025-1260, ensure that you upgrade to the latest version of Arista EOS that addresses this vulnerability.
What are the potential impacts of CVE-2025-1260?
The potential impacts of CVE-2025-1260 include unauthorized configuration changes and disruptions to network operations.
Which versions of Arista EOS are affected by CVE-2025-1260?
All versions of Arista EOS configured with OpenConfig are potentially affected by CVE-2025-1260.
Is there a workaround for CVE-2025-1260?
While the primary mitigation is an upgrade, users may also restrict gNOI requests as an interim workaround to mitigate risks from CVE-2025-1260.