← Back

CVE-2021-28503

nvd nist
Published: Feb 4, 2022Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate based authentication is used, which allows remote attackers to access the device via eAPI.

Affected (5)

Products: Arista: Eos
1 product
Eos
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Arista
From 4.22 to 4.22.9m
From 4.23 to 4.23.9
From 4.24 to 4.24.7
From 4.25 to 4.25.5
From 4.26 to 4.26.2

References (2)

Timeline

No history available yet.