CVE-2021-28501: An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.
An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this Arista EOS issue?
The vulnerability ID for this Arista EOS issue is CVE-2021-28501.
What is the severity of CVE-2021-28501?
The severity of CVE-2021-28501 is critical with a CVSS score of 7.8.
Which software versions are affected by CVE-2021-28501?
Arista TerminAttr version up to and including 1.16.2 is affected by CVE-2021-28501.
How can the incorrect use of EOS's AAA API's result in unrestricted access to the device?
The incorrect use of EOS's AAA API's by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with no password configuration.
Where can I find more information about CVE-2021-28501 and its mitigation?
You can find more information about CVE-2021-28501 and its mitigation in the Arista Security Advisory 0071 at https://www.arista.com/en/support/advisories-notices/security-advisories/13449-security-advisory-0071.