CVE-2021-28496: In Arista's EOS software affected releases, the shared secret profiles sensitive configuration might be leaked when displaying output over eAPI or other JSON outputs to authenticated users on the device.
On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the password configured for use by BiDirectional Forwarding Detection (BFD) will be leaked when displaying output over eAPI or other JSON outputs to other authenticated users on the device. The affected EOS Versions are: all releases in 4.22.x train, 4.23.9 and below releases in the 4.23.x train, 4.24.7 and below releases in the 4.24.x train, 4.25.4 and below releases in the 4.25.x train, 4.26.1 and below releases in the 4.26.x train
Affected Software
Remediation
Information
Information
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2021-28496.
What software is affected by this vulnerability?
Systems running Arista EOS and CloudEOS with the affected release versions are affected.
What is the severity level of CVE-2021-28496?
The severity level of CVE-2021-28496 is medium (6.5).
How can the password leakage be exploited?
The password configured for use by BiDirectional Forwarding Detection (BFD) can be leaked when displaying output over eAPI or other JSON outputs to other authenticated users on the device.
How can I fix CVE-2021-28496?
Apply the necessary patches or updates provided by Arista to fix CVE-2021-28496.