CVE-2021-28503

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
04/02/2022
Last modified:
02/08/2022

Description

The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate based authentication is used, which allows remote attackers to access the device via eAPI.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* 4.22 (including) 4.22.9m (including)
cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* 4.23 (including) 4.23.9 (including)
cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* 4.24 (including) 4.24.7 (including)
cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* 4.25 (including) 4.25.5 (including)
cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* 4.26 (including) 4.26.2 (including)