PT-2022-9898 · Arista · Arista Eos

Published

2022-01-11

·

Updated

2022-07-14

·

CVE-2021-28506

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions Arista EOS (affected versions not specified)
Description An issue has been discovered where certain gNOI APIs in Arista EOS incorrectly skip authorization and authentication, potentially allowing a factory reset of the device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Missing Authorization

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-28506

Affected Products

Arista Eos