CVE-2021-28496
published 2021-10-21CVE-2021-28496: On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the password configured for use by…
PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.42%
33.3th percentile
On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the password configured for use by BiDirectional Forwarding Detection (BFD) will be leaked when displaying output over eAPI or other JSON outputs to other authenticated users on the device. The affected EOS Versions are: all releases in 4.22.x train, 4.23.9 and below releases in the 4.23.x train, 4.24.7 and below releases in the 4.24.x train, 4.25.4 and below releases in the 4.25.x train, 4.26.1 and below releases in the 4.26.x train
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| arista | eos | 4.22 – 4.22.7m | — |
| arista | eos | >= 4.23 < 4.23.10 | 4.23.10 |
| arista | eos | >= 4.24 < 4.24.8 | 4.24.8 |
| arista | eos | >= 4.25 < 4.25.5 | 4.25.5 |
| arista | eos | >= 4.26 < 4.26.2 | 4.26.2 |
| arista_networks | arista_eos | EOS-4.22 – EOS-4.22.12 | — |
| arista_networks | arista_eos | >= EOS-4.23 < EOS-4.23.10 | EOS-4.23.10 |
| arista_networks | arista_eos | >= EOS-4.24 < EOS-4.24.8 | EOS-4.24.8 |
| arista_networks | arista_eos | >= EOS-4.25 < EOS-4.25.5 | EOS-4.25.5 |
| arista_networks | arista_eos | >= EOS-4.26 < EOS-4.26.2 | EOS-4.26.2 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-10-21
Published