7.1
CVSSv3

CVE-2021-28507

Published: 14/01/2022 Updated: 14/07/2022
CVSS v2 Base Score: 4.9 | Impact Score: 4.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 7.1 | Impact Score: 4.2 | Exploitability Score: 2.8
VMScore: 436
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N

Vulnerability Summary

An issue has recently been discovered in Arista EOS where, under certain conditions, the service ACL configured for OpenConfig gNOI and OpenConfig RESTCONF might be bypassed, which results in the denied requests being forwarded to the agent.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

arista eos 4.21.0f

arista eos 4.21.1f

arista eos 4.22.0f

arista eos 4.22.1f

arista eos

arista eos 4.21.3f