CVE-2025-54545

7.8

Arista Networks · DANZ Monitoring Fabric (DMF)

A restricted user can escape the CLI sandbox on affected Arista Networks products to achieve system shell access and escalate privileges.

Executive summary

A high-severity sandbox escape vulnerability in Arista Networks software allows authenticated local users to escalate privileges to the system shell, posing a significant risk to device integrity.

Vulnerability

This vulnerability, categorized as CWE-732 (Incorrect Permission Assignment for Critical Resource), allows an authenticated user with restricted command-line interface access to bypass sandbox restrictions. By escaping the intended constraints, an attacker can execute arbitrary commands with elevated system-level privileges.

Business impact

Successful exploitation of this vulnerability results in a total loss of confidentiality, integrity, and availability for the affected network appliance. With a CVSS score of 7.8, this flaw represents a high risk to business operations, as an attacker could gain full control over monitoring infrastructure, potentially leading to unauthorized network traffic inspection, configuration changes, or complete system compromise.

Remediation

Immediate Action: Upgrade all affected systems to the latest remediated software versions, specifically DMF 8.7.1, 8.6.2, 8.5.3, 8.4.6, or their respective later releases as provided in the vendor security advisory.

Proactive Monitoring: Review administrative access logs for unusual command execution patterns or attempts to access restricted shell environments by non-privileged accounts.

Compensating Controls: Strictly limit administrative access to the command-line interface to trusted personnel only, and employ network-level segmentation to reduce the potential impact if a device is compromised.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the potential for full system compromise, security teams should prioritize patching Arista network appliances during the next maintenance window. The ability to escape a restricted shell environment undermines the fundamental security controls of the platform, making immediate application of the vendor-supplied updates the only effective method to eliminate this risk.

More Arista Networks CVEs

Sources