An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-15177 An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.
Fixes

Solution

The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release. To specifically address CVE-2021-28501 upgrade to TerminAttr v1.16.2 and later releases


Workaround

On the affected versions, all vulnerabilities can be mitigated by disabling OpenConfig gNMI/gNOI and OpenConfig RESTCONF and TerminAttr. If use of these agents is required, a hotfix employing a proxy service can be deployed.

History

Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00291}

epss

{'score': 0.00138}


cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2024-09-17T03:43:50.014Z

Reserved: 2021-03-16T00:00:00

Link: CVE-2021-28501

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-01-14T20:15:10.267

Modified: 2024-11-21T05:59:47.573

Link: CVE-2021-28501

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.