Description
This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig transport protocols. The impact of this vulnerability is that, in certain conditions, TerminAttr might leak MACsec sensitive data in clear text in CVP to other authorized users, which could cause MACsec traffic to be decrypted or modified by other authorized users on the device.
Published: 2022-05-26
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

The recommended resolution is to upgrade to a remediated software version at your earliest convenience. The vulnerability is fixed in the following versions: EOS versions: 4.24.10 and later release in the 4.24.x train 4.25.8 and later releases in the 4.25.x train 4.26.6 and later releases in the 4.26.x train 4.27.4 and later releases in the 4.27.x train TerminAttr versions: TerminAttr v1.10.11 and later releases in the v1.10.x train TerminAttr v1.16.8 and later releases in the v1.16.x train TerminAttr v1.19.2 and later releases


Vendor Workaround

On the affected versions, the vulnerabilities can be mitigated by disabling TerminAttr agent.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-15185 This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig transport protocols. The impact of this vulnerability is that, in certain conditions, TerminAttr might leak MACsec sensitive data in clear text in CVP to other authorized users, which could cause MACsec traffic to be decrypted or modified by other authorized users on the device.
History

No history.

Subscriptions

Arista 7050cx3-32s 7050cx3m-32s 7050sx3-48c8 7050sx3-48yc 7050sx3-48yc12 7050sx3-48yc8 7050sx3-96yc8 7050tx3-48c8 7280cr2ak-30 7280cr2k-60 7280cr3-32d4 7280cr3-32p4 7280cr3-96 7280cr3k-32d4 7280cr3k-32p4 7280cr3k-96 7280dr3-24 7280dr3k-24 7280pr3-24 7280pr3k-24 7280r2 7280r3 7280sr3-48yc8 7280sr3k-48yc8 7388x5 7500r2 7500r3 7500r3-24d 7500r3-24p 7500r3-36cq 7500r3k-36cq 7800r3-36p 7800r3-48cq 7800r3k-48cq Ccs-722xpm-48y4 Ccs-722xpm-48zy8 Dcs-7050cx3-32s Dcs-7050cx3-32s-r Dcs-7050cx3m-32s Dcs-7050sx3-48c8 Dcs-7050sx3-48yc12 Dcs-7050sx3-48yc8 Dcs-7050sx3-96yc8 Eos Terminattr
cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2024-09-16T20:32:30.399Z

Reserved: 2021-03-16T00:00:00.000Z

Link: CVE-2021-28509

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-05-26T20:15:08.500

Modified: 2024-11-21T05:59:48.463

Link: CVE-2021-28509

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses