PT-2022-9899 · Arista · Arista Eos

Published

2022-01-11

·

Updated

2022-07-14

·

CVE-2021-28507

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Arista EOS (affected versions not specified)
Description An issue has been discovered where, under certain conditions, the service ACL configured for OpenConfig gNOI and OpenConfig RESTCONF might be bypassed, resulting in denied requests being forwarded to the agent.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-28507

Affected Products

Arista Eos