CVE-2021-28510

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/01/2023
Last modified:
30/06/2023

Description

For certain systems running EOS, a Precision Time Protocol (PTP) packet of a management/signaling message with an invalid Type-Length-Value (TLV) causes the PTP agent to restart. Repeated restarts of the service will make the service unavailable.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* 4.23.10 (excluding)
cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* 4.24.0 (including) 4.24.8 (excluding)
cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* 4.25.0 (including) 4.25.6 (excluding)
cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* 4.26.0 (including) 4.26.4 (excluding)
cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* 4.27.0 (including) 4.27.1 (excluding)
cpe:2.3:h:arista:7020r:-:*:*:*:*:*:*:*
cpe:2.3:h:arista:7050cx3-32s:-:*:*:*:*:*:*:*
cpe:2.3:h:arista:7050cx3m-32s:-:*:*:*:*:*:*:*
cpe:2.3:h:arista:7050qx-32s:-:*:*:*:*:*:*:*
cpe:2.3:h:arista:7050qx2-32s:-:*:*:*:*:*:*:*
cpe:2.3:h:arista:7050sx-128:-:*:*:*:*:*:*:*
cpe:2.3:h:arista:7050sx-64:-:*:*:*:*:*:*:*
cpe:2.3:h:arista:7050sx-72q:-:*:*:*:*:*:*:*
cpe:2.3:h:arista:7050sx2-128:-:*:*:*:*:*:*:*
cpe:2.3:h:arista:7050sx2-72q:-:*:*:*:*:*:*:*