PT-2022-9893 · Arista · Arista Eos

Published

2022-01-11

·

Updated

2023-08-17

·

CVE-2021-28500

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Arista EOS (affected versions not specified)
Description An issue has been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-28500

Affected Products

Arista Eos