Beveiligingsadvies

CVE-2021-28503

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-02-04 22:29:27
Laatst bijgewerkt 2024-09-16 23:06:02
Toegewezen door Arista
CVSS-score 7.4
Status PUBLISHED

Beschrijving

The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate based authentication is used, which allows remote attackers to access the device via eAPI.