On affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File TransferToRemote RPC with credentials for a remote server may cause these remote-server credentials to be logged or accounted on the local EOS device or possibly on other remote accounting servers (i.e. TACACS, RADIUS, etc).
History

Thu, 08 May 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 May 2025 23:00:00 +0000

Type Values Removed Values Added
Description On affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File TransferToRemote RPC with credentials for a remote server may cause these remote-server credentials to be logged or accounted on the local EOS device or possibly on other remote accounting servers (i.e. TACACS, RADIUS, etc).
Title On affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File TransferToRemote RPC with credentials for a remote server may cause these remote-server credentials to be logged or accounted on the local EOS device or possibly
Weaknesses CWE-256
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published: 2025-05-07T22:52:25.444Z

Updated: 2025-05-08T13:02:27.046Z

Reserved: 2025-01-31T17:18:43.715Z

Link: CVE-2025-0936

cve-icon Vulnrichment

Updated: 2025-05-08T13:02:17.684Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-07T23:15:53.010

Modified: 2025-05-08T14:39:09.683

Link: CVE-2025-0936

cve-icon Redhat

No data.