ZeroHour

CVE-2021-28501

PoC
CVSS 3.1
7.8 high
EPSS
<1%p56
Published
()
Modified
Description

An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.

Vendors
arista
Products
terminattr
Weakness
CWE-285
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.