CVE-2021-28503: In Arista's EOS software affected releases, eAPI might skip re-evaluating user credentials when certificate based authentication is used, which allows remote attackers to access the device via eAPI.
Published Feb 4, 2022
·Updated
The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate based authentication is used, which allows remote attackers to access the device via eAPI.
Affected Software
5 affected components
Arista EOS>=4.22<=4.22.9m
Arista EOS>=4.23<=4.23.9
Arista EOS>=4.24<=4.24.7
Arista EOS>=4.25<=4.25.5
Arista EOS>=4.26<=4.26.2
Remediation
Information
The recommended resolution is to upgrade to a remediated software version at your earliest convenience.
The vulnerability is fixed in the following EOS versions:
4.26.3 and later releases in the 4.26.x train
4.25.6 and later releases in the 4.25.x train
4.24.8 and later releases in the 4.24.x train
4.23.10 and later releases in the 4.24.x train
Event History
Feb 4, 2022
CVE Published
via MITRE·10:29 PM
Data Sourced
via MITRE·10:29 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-28503?
CVE-2021-28503 is a vulnerability in Arista's EOS eAPI that allows remote attackers to access the device via eAPI.
2
What is the impact of CVE-2021-28503?
The impact of CVE-2021-28503 is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate-based authentication is used.
3
How can remote attackers exploit CVE-2021-28503?
Remote attackers can exploit CVE-2021-28503 to access the device via eAPI.
4
What is the severity of CVE-2021-28503?
CVE-2021-28503 has a severity rating of 9.8 (critical).
5
How can I fix CVE-2021-28503?
To fix CVE-2021-28503, update Arista's EOS to version 4.22.9m, 4.23.9, 4.24.7, 4.25.5, or 4.26.2.