Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-15180 | On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which matches on “vxlan” as protocol then that rule and subsequent rules ( rules declared after it in ACL ) do not match on IP protocol field as expected. |
Solution
The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Artista recommends customers move to the latest version of each release that contains all the fixes listed below. CVE-2021-28504 has been fixed in the following releases: 4.26.4F and later releases in the 4.26.x train 4.27.1M and later releases in the 4.27.x train
Workaround
Replace "vxlan" IP protocol match with match on IP protocol "udp" and Layer 4 destination port for VxLAN encapsulated packets i.e 4789. If VXLAN L4 destination port number is not the default 4789 then use the configured L4 destination port number.
No history.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2024-08-03T21:47:32.630Z
Reserved: 2021-03-16T00:00:00
Link: CVE-2021-28504
No data.
Status : Modified
Published: 2022-04-01T23:15:09.380
Modified: 2024-11-21T05:59:47.823
Link: CVE-2021-28504
No data.
OpenCVE Enrichment
No data.
EUVD