CVE-2021-28511
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitability: 3.9 / Impact: 2.5
Source: NVD
Description
This advisory documents the impact of an internally found vulnerability in Arista EOS for security ACL bypass. The impact of this vulnerability is that the security ACL drop rule might be bypassed if a NAT ACL rule filter with permit action matches the packet flow. This could allow a host with an IP address in a range that matches the range allowed by a NAT ACL and a range denied by a Security ACL to be forwarded incorrectly as it should have been denied by the Security ACL. This can enable an ACL bypass.
Affected (4)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.24.9 |
| Running on/with | Platform Versions |
|---|---|
Arista 7050cx3 32s | All versions |
Arista 7050cx3m 32s | All versions |
Arista 7050sx3 48c8 | All versions |
Arista 7050sx3 48yc | All versions |
Arista 7050sx3 48yc12 | All versions |
Arista 7050sx3 48yc8 | All versions |
Arista 7050sx3 96yc8 | All versions |
Arista 7050tx3 48c8 | All versions |
Arista 720xp 24y6 | All versions |
Arista 720xp 24zy4 | All versions |
Arista 720xp 48y6 | All versions |
Arista 720xp 48zc2 | All versions |
Arista 720xp 96zc2 | All versions |
Arista 7300x3 32c | All versions |
Arista 7300x3 48yc4 | All versions |
References (2)
Source: psirt@arista.com
ExploitMitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMitigationVendor Advisory
Timeline
No history available yet.