An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.
References
Link | Resource |
---|---|
https://www.arista.com/en/support/advisories-notices/security-advisories/13449-security-advisory-0071 | Exploit Mitigation Patch Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: Arista
Published: 2022-01-11T00:00:00
Updated: 2022-01-14T19:11:36
Reserved: 2021-03-16T00:00:00
Link: CVE-2021-28500
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-01-14T20:15:10.217
Modified: 2023-08-17T14:47:30.057
Link: CVE-2021-28500
JSON object: View
Redhat Information
No data.
CWE