CVE-2021-28503
04.02.2022, 23:15
The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate based authentication is used, which allows remote attackers to access the device via eAPI.Enginsight
Vendor | Product | Version |
---|---|---|
arista | eos | 4.22 ≤ 𝑥 ≤ 4.22.9m |
arista | eos | 4.23 ≤ 𝑥 ≤ 4.23.9 |
arista | eos | 4.24 ≤ 𝑥 ≤ 4.24.7 |
arista | eos | 4.25 ≤ 𝑥 ≤ 4.25.5 |
arista | eos | 4.26 ≤ 𝑥 ≤ 4.26.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-305 - Authentication Bypass by Primary WeaknessThe authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.
- CWE-287 - Improper AuthenticationWhen an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.