Synced 16 Jun 2026 15:24 UTC Account
← All products

CVE-2021-28500

CRITICAL severity · CVSS 9.1 · CWE-285
9.1CVSS CRITICAL

Summary

An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.

Impact & exploitability

Attack vectorNetwork
Attack complexityLow
Privileges requiredNone
User interactionNone
Confidentiality impactNone
Integrity impactHigh
Availability impactHigh
Exploit probability (EPSS)1%

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Affected products we track (1)

EOS

Recommendation

Apply the vendor fix promptly. Open any affected product above for its exact safe version.

Official patch: https://www.arista.com/en/support/advisories-notices/security-advisories/13449-security-advisory-0071 ↗