Security Advisory Tests
This page documents each security advisory test currently implemented in ANTA. See the Security Advisory Tests Overview for the support matrix.
SA117 ¶
Preview
Input models and behavior may change between minor releases without a deprecation notice.
Assess SA117 credential exposure through OpenConfig accounting or tracing.
Notes
Exposure signals remain inconclusive because disabling the gNOI File service and an effective gNSI Authz policy that blocks TransferToRemote cannot currently be evaluated with trusted narrow EOS evidence.
Expected Results
- Success: The test will pass if the EOS version or configuration is not affected.
- Inconclusive: The test is inconclusive if exposure signals exist but required control evidence is unavailable.
- Error: The test will error if required EOS version or configuration evidence is invalid.
Security advisory: Security Advisory 0117
SA140 ¶
Preview
Input models and behavior may change between minor releases without a deprecation notice.
Verify that the advisory 140 Secure Boot exposure is absent.
Expected Results
- Success: The test will pass if the EOS version or Secure Boot state is not affected.
- Failure: The test will fail if an affected EOS version has Secure Boot supported and enabled.
- Error: The test will error if the EOS version or Secure Boot state cannot be determined.
Security advisory: Security Advisory 0140
SA142 ¶
Preview
Input models and behavior may change between minor releases without a deprecation notice.
Verify that Security Advisory 142 next-hop redirects are fully remediated.
Notes
This test currently requires the structured EOS platform identity supplied by AsyncEOSDevice.
Incomplete modular identities remain inconclusive when the installed modules cannot establish the affected family.
Expected Results
- Success: The test will pass if no affected redirect path is active or a conditional fix is complete.
- Failure: The test will fail if a vulnerable redirect path is active or a conditional fix is incomplete.
- Inconclusive: The test is inconclusive for a conservatively matched chassis.
- Error: The test will error if a required redirect, platform, EOS release, or MTU control state cannot be determined.
Security advisory: Security Advisory 0142
SA146 ¶
Preview
Input models and behavior may change between minor releases without a deprecation notice.
Assess the SA146 HTTP/2 Rapid Reset exposure and documented mTLS control.
Notes
TerminAttr validates its configured certificate, private key, and client CA files when it starts. A running TerminAttr process configured with the complete mTLS arguments therefore has valid files and enforces mTLS. If file validation prevents TerminAttr from starting, its gRPC service is not exposed. The TerminAttr mTLS path is therefore safely classified as mitigated.
Expected Results
- Success: The test will pass if no affected gRPC service is enabled.
- Failure: The test will fail if an affected gRPC service is enabled without mTLS.
- Mitigated: The test is mitigated if all affected services are protected with mTLS.
- Error: The test will error if a required service, EOS release, component version, or mTLS state cannot be determined.
Security advisory: Security Advisory 0146
SA147 ¶
Preview
Input models and behavior may change between minor releases without a deprecation notice.
Verify the four independent OpenSSH issues in Security Advisory 147.
Strict host-key checking is an observable identity control for CVE-2026-60002, but it does not establish that operators connect only to trusted servers as required by the advisory. An affected release with strict host-key checking is therefore inconclusive rather than mitigated.
Expected Results
- Success: The test will pass if every vulnerability is not affected.
- Failure: The test will fail if any vulnerability is affected or inconclusive.
- Error: The test will error if evidence required for a vulnerability is invalid.
Security advisory: Security Advisory 0147