Vulnerability Details CVE-2021-28504
On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which matches on “vxlan” as protocol then that rule and subsequent rules ( rules declared after it in ACL ) do not match on IP protocol field as expected.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 40.8%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 4.3
Products affected by CVE-2021-28504
-
cpe:2.3:h:arista:ccs-710p-12:-
-
cpe:2.3:h:arista:ccs-710p-16p:-
-
cpe:2.3:h:arista:ccs-720xp-24y6:-
-
cpe:2.3:h:arista:ccs-720xp-24zy4:-
-
cpe:2.3:h:arista:ccs-720xp-48y6:-
-
cpe:2.3:h:arista:ccs-720xp-48zc2:-
-
cpe:2.3:h:arista:ccs-720xp-96zc2:-
-
cpe:2.3:h:arista:ccs-722xpm-48y4:-
-
cpe:2.3:h:arista:ccs-722xpm-48zy8:-
-
cpe:2.3:h:arista:dcs-7010tx-48:-
-
cpe:2.3:h:arista:dcs-7050cx3-32s:-
-
cpe:2.3:h:arista:dcs-7050cx3m-32s:-
-
cpe:2.3:h:arista:dcs-7050sx3-48c8:-
-
cpe:2.3:h:arista:dcs-7050sx3-48yc12:-
-
cpe:2.3:h:arista:dcs-7050sx3-48yc8:-
-
cpe:2.3:h:arista:dcs-7050sx3-96yc8:-
-
cpe:2.3:h:arista:dcs-7050tx3-48c8:-
-
cpe:2.3:o:arista:eos:4.26
-
cpe:2.3:o:arista:eos:4.26.0
-
cpe:2.3:o:arista:eos:4.26.1
-
cpe:2.3:o:arista:eos:4.26.1f
-
cpe:2.3:o:arista:eos:4.26.2
-
cpe:2.3:o:arista:eos:4.26.2f
-
cpe:2.3:o:arista:eos:4.26.3m
-
cpe:2.3:o:arista:eos:4.26.4
-
cpe:2.3:o:arista:eos:4.27
-
cpe:2.3:o:arista:eos:4.27.0
-
cpe:2.3:o:arista:eos:4.27.0f
-
cpe:2.3:o:arista:eos:4.27.1