First published: Fri Jan 14 2022(Updated: )
An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.
Credit: psirt@arista.com
Affected Software | Affected Version | How to fix |
---|---|---|
Arista Terminattr | <=1.16.2 |
The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release. To specifically address CVE-2021-28501 upgrade to TerminAttr v1.16.2 and later releases
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Arista EOS issue is CVE-2021-28501.
The severity of CVE-2021-28501 is critical with a CVSS score of 7.8.
Arista TerminAttr version up to and including 1.16.2 is affected by CVE-2021-28501.
The incorrect use of EOS's AAA API's by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with no password configuration.
You can find more information about CVE-2021-28501 and its mitigation in the Arista Security Advisory 0071 at https://www.arista.com/en/support/advisories-notices/security-advisories/13449-security-advisory-0071.