CVE-2021-28508: TerminAttr streams IPsec sensitive data in clear text to other authorized users in CVP
This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig transport protocols. The impact of this vulnerability is that, in certain conditions, TerminAttr might leak IPsec sensitive data in clear text in CVP to other authorized users, which could cause IPsec traffic to be decrypted or modified by other authorized users on the device.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-28508?
CVE-2021-28508 is an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig transport protocols that can leak IPsec sensitive data in clear text in CVP to other systems.
Which software is affected by CVE-2021-28508?
Arista TerminAttr versions 1.10.11, 1.11.0 to 1.16.8, and 1.17.0 to 1.19.0 as well as Arista EOS versions 4.23 to 4.23.11, 4.24 to 4.24.10, 4.25 to 4.25.8, 4.26 to 4.26.6, and 4.27 to 4.27.2 are affected by CVE-2021-28508.
What is the severity of CVE-2021-28508?
CVE-2021-28508 has a severity level of medium with a CVSS score of 6.1.
How can I fix CVE-2021-28508?
To fix CVE-2021-28508, it is recommended to upgrade to a non-vulnerable version of Arista TerminAttr or Arista EOS.
Where can I find more information about CVE-2021-28508?
More information about CVE-2021-28508 can be found in the Arista Security Advisory 0077 at this link: [https://www.arista.com/en/support/advisories-notices/security-advisories/15484-security-advisory-0077]