« Volver al listado

CVE-2021-28503

Estado: ModificadaCrítica (9.8)—

The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate based authentication is used, which allows remote attackers to access the device via eAPI.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-28503",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@arista.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.4,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 2.2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@arista.com",
      "affectedData": [
        {
          "vendor": "Arista Networks",
          "product": "Arista EOS",
          "versions": [
            {
              "status": "affected",
              "version": "EOS-4.23",
              "lessThan": "EOS-4.23.10",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "EOS-4.24",
              "lessThan": "EOS-4.24.8",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "EOS-4.25",
              "lessThan": "EOS-4.25.6",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "EOS-4.26",
              "lessThan": "EOS-4.26.3",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-02-04T23:15:11.350",
  "references": [
    {
      "url": "https://www.arista.com/en/support/advisories-notices/security-advisories/13605-security-advisory-0072",
      "tags": [
        "Mitigation",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "psirt@arista.com"
    },
    {
      "url": "https://www.arista.com/en/support/advisories-notices/security-advisories/13605-security-advisory-0072",
      "tags": [
        "Mitigation",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@arista.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-305"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate based authentication is used, which allows remote attackers to access the device via eAPI."
    },
    {
      "lang": "es",
      "value": "El impacto de esta vulnerabilidad es que EOS eAPI de Arista puede omitir la reevaluación de las credenciales del usuario cuando es usada la autenticación basada en certificados, lo que permite a atacantes remotos acceder al dispositivo por medio de eAPI"
    }
  ],
  "lastModified": "2026-06-17T03:46:28.667",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C48331B8-808D-4080-BD74-2DC93014D10C",
              "versionEndIncluding": "4.22.9m",
              "versionStartIncluding": "4.22"
            },
            {
              "criteria": "cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A3310AD8-03C5-4018-A49B-C3527B9C2ADB",
              "versionEndIncluding": "4.23.9",
              "versionStartIncluding": "4.23"
            },
            {
              "criteria": "cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AFB2FFFE-6E99-4222-B3F4-854B5A4B8B0A",
              "versionEndIncluding": "4.24.7",
              "versionStartIncluding": "4.24"
            },
            {
              "criteria": "cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E004CBA8-2859-4098-948B-2F5D0DD5EBA5",
              "versionEndIncluding": "4.25.5",
              "versionStartIncluding": "4.25"
            },
            {
              "criteria": "cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "06AA619C-3D2F-41FC-A3F1-0080F57A8F09",
              "versionEndIncluding": "4.26.2",
              "versionStartIncluding": "4.26"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@arista.com"
}