CVE-2021-28506: An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a factory reset of the device.
An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a factory reset of the device.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue in Arista EOS?
The vulnerability ID for this issue in Arista EOS is CVE-2021-28506.
What is the severity of CVE-2021-28506?
The severity of CVE-2021-28506 is critical with a severity value of 9.1.
Which versions of Arista EOS are affected by CVE-2021-28506?
Versions 4.24.0 to 4.24.7m, 4.25.0 to 4.25.3, 4.25.4, 4.25.5 to 4.25.5.1m, and 4.26.0 to 4.26.2f of Arista EOS are affected by CVE-2021-28506.
What is the impact of CVE-2021-28506?
CVE-2021-28506 could potentially allow a factory reset of the affected Arista EOS device.
How can I fix CVE-2021-28506 in Arista EOS?
Arista has released a security advisory (reference: https://www.arista.com/en/support/advisories-notices/security-advisories/13449-security-advisory-0071) with instructions on how to mitigate the vulnerability in Arista EOS.