CVE-2021-28510

Severity
7.5HIGH
EPSS
0.6%
top 31.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 26

Description

For certain systems running EOS, a Precision Time Protocol (PTP) packet of a management/signaling message with an invalid Type-Length-Value (TLV) causes the PTP agent to restart. Repeated restarts of the service will make the service unavailable.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

NVDarista/eos4.24.04.24.8+4
CVEListV5arista_networks/eos4.27.14.27.0+5

🔴Vulnerability Details

2
GHSA
GHSA-c5c5-rwc6-67m5: For certain systems running EOS, a Precision Time Protocol (PTP) packet of a management/signaling message with an invalid Type-Length-Value (TLV) caus2023-01-26
CVEList
For certain systems running EOS, a Precision Time Protocol (PTP) packet of a management/signaling message with an invalid Type-Length-Value (TLV) causes the PTP agent to restart. Repeated restarts of 2023-01-24