Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-15180 | On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which matches on “vxlan” as protocol then that rule and subsequent rules ( rules declared after it in ACL ) do not match on IP protocol field as expected. |
Solution
The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Artista recommends customers move to the latest version of each release that contains all the fixes listed below. CVE-2021-28504 has been fixed in the following releases: 4.26.4F and later releases in the 4.26.x train 4.27.1M and later releases in the 4.27.x train
Workaround
Replace "vxlan" IP protocol match with match on IP protocol "udp" and Layer 4 destination port for VxLAN encapsulated packets i.e 4789. If VXLAN L4 destination port number is not the default 4789 then use the configured L4 destination port number.
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2024-08-03T21:47:32.630Z
Reserved: 2021-03-16T00:00:00
Link: CVE-2021-28504
No data.
Status : Modified
Published: 2022-04-01T23:15:09.380
Modified: 2024-11-21T05:59:47.823
Link: CVE-2021-28504
No data.
OpenCVE Enrichment
No data.
EUVD