CVE-2021-28504

HIGH

Arista EOS 4.26-4.26.4m - Improper Access Control via TCAM Profile VXLAN Protocol Rule

Title source: llm
STIX 2.1

Description

On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which matches on “vxlan” as protocol then that rule and subsequent rules ( rules declared after it in ACL ) do not match on IP protocol field as expected.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0071
EPSS Percentile 48.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-284 CWE-863
Status published
Products (1)
arista/eos 4.26 - 4.26.4m
Published Apr 01, 2022
Tracked Since Feb 18, 2026