CVE-2021-28510: For certain systems running EOS, a Precision Time Protocol (PTP) packet of a management/signaling message with an invalid Type-Length-Value (TLV) causes the PTP agent to restart. Repeated restarts of the service will make the service unavailable.
For certain systems running EOS, a Precision Time Protocol (PTP) packet of a management/signaling message with an invalid Type-Length-Value (TLV) causes the PTP agent to restart. Repeated restarts of the service will make the service unavailable.
Affected Software
Remediation
Information
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28510?
CVE-2021-28510 is considered medium severity due to the potential for service interruption.
How do I fix CVE-2021-28510?
To fix CVE-2021-28510, upgrade to a version of Arista EOS that is beyond 4.23.10 or the specified vulnerable versions.
Which systems are affected by CVE-2021-28510?
CVE-2021-28510 affects various versions of Arista EOS including those up to 4.23.10 and certain ranges from 4.24.0 to 4.26.4 and beyond.
What happens if CVE-2021-28510 is exploited?
If exploited, CVE-2021-28510 causes the Precision Time Protocol (PTP) agent to continuously restart, making the service unavailable.
Is there a workaround for CVE-2021-28510?
There is no official workaround for CVE-2021-28510 other than upgrading to a patched version of Arista EOS.