CVE-2021-28501

CRITICAL

Arista TerminAttr < 1.16.2 - Unauthenticated Unrestricted Device Access via AAA API Misuse

Title source: llm
STIX 2.1

Description

An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.

References (1)

Core 1
Core References

Scores

CVSS v3 9.1
EPSS 0.0084
EPSS Percentile 53.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Details

CWE
CWE-285
Status published
Products (1)
arista/terminattr < 1.16.2
Published Jan 14, 2022
Tracked Since Feb 18, 2026