Security Advisory

CVE-2021-28503

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-02-04 22:29:27
Last updated 2024-09-16 23:06:02
Assigner Arista
CVSS score 7.4
State PUBLISHED

Description

The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate based authentication is used, which allows remote attackers to access the device via eAPI.