An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published: 2022-01-14T19:11:36.486990Z

Updated: 2024-09-16T18:44:53.535Z

Reserved: 2021-03-16T00:00:00

Link: CVE-2021-28500

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-01-14T20:15:10.217

Modified: 2023-08-17T14:47:30.057

Link: CVE-2021-28500

cve-icon Redhat

No data.