In Arista's EOS software affected releases, eAPI might skip re-evaluating user credentials when certificate based authentication is used, which allows remote attackers to access the device via eAPI.
CVE-2021-28503
7.4HIGH
What is CVE-2021-28503?
The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate based authentication is used, which allows remote attackers to access the device via eAPI.
Affected Version(s)
Arista EOS EOS-4.23
Arista EOS EOS-4.24
Arista EOS EOS-4.25