Arista Networks Terminattr vulnerabilities
2 known vulnerabilities affecting arista_networks/terminattr.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2023-24512MEDIUMCVSS 6.5v1.23.0≥ unspecified, ≤ 1.19.5+2 more2023-04-25
CVE-2023-24512 [HIGH] CWE-284 CVE-2023-24512: On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI re
On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a request allowing it to update arbitrary configurations in the switch. This situation occurs only when the Streaming Telemetry Agent (referred to as the TerminAttr agent) is enabled and gNMI access is configured on the agent. Note: T
cvelistv5nvd
CVE-2021-28501HIGHCVSS 7.8v1.16.2 02022-01-14
CVE-2021-28501 [CRITICAL] CWE-285 CVE-2021-28501: An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by th
An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.
cvelistv5nvd