An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published: 2022-01-14T19:04:48.898457Z

Updated: 2024-09-17T03:43:50.014Z

Reserved: 2021-03-16T00:00:00

Link: CVE-2021-28501

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-01-14T20:15:10.267

Modified: 2022-07-14T18:38:22.480

Link: CVE-2021-28501

cve-icon Redhat

No data.