An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a factory reset of the device.
CVE-2021-28506
9.1CRITICAL
What is CVE-2021-28506?
An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a factory reset of the device.
Affected Version(s)
EOS 4.26.2F <= 4.26.0
EOS 4.25.5.1M <= 4.25.5
EOS 4.25.4M <= 4.25.4