cbcvebase.
CVE-2021-28496
published 2021-10-21

CVE-2021-28496: On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the password configured for use by…

PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.42%
33.3th percentile
On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the password configured for use by BiDirectional Forwarding Detection (BFD) will be leaked when displaying output over eAPI or other JSON outputs to other authenticated users on the device. The affected EOS Versions are: all releases in 4.22.x train, 4.23.9 and below releases in the 4.23.x train, 4.24.7 and below releases in the 4.24.x train, 4.25.4 and below releases in the 4.25.x train, 4.26.1 and below releases in the 4.26.x train

Affected

10 ranges
VendorProductVersion rangeFixed in
aristaeos4.22 – 4.22.7m
aristaeos>= 4.23 < 4.23.104.23.10
aristaeos>= 4.24 < 4.24.84.24.8
aristaeos>= 4.25 < 4.25.54.25.5
aristaeos>= 4.26 < 4.26.24.26.2
arista_networksarista_eosEOS-4.22 – EOS-4.22.12
arista_networksarista_eos>= EOS-4.23 < EOS-4.23.10EOS-4.23.10
arista_networksarista_eos>= EOS-4.24 < EOS-4.24.8EOS-4.24.8
arista_networksarista_eos>= EOS-4.25 < EOS-4.25.5EOS-4.25.5
arista_networksarista_eos>= EOS-4.26 < EOS-4.26.2EOS-4.26.2

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.