CVE-2021-28506

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
14/01/2022
Last modified:
14/07/2022

Description

An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a factory reset of the device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* 4.24.0 (including) 4.24.7m (including)
cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* 4.25.0 (including) 4.25.3 (including)
cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* 4.25.4 (including) 4.25.4m (including)
cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* 4.25.5 (including) 4.25.5.1m (including)
cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* 4.26.0 (including) 4.26.2f (including)