Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-28506

An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a factory reset of the device.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 51.1%
CVSS Severity
CVSS v3 Score 9.1
CVSS v2 Score 9.4
Products affected by CVE-2021-28506
  • Arista » Eos » Version: 4.24.0
    cpe:2.3:o:arista:eos:4.24.0
  • Arista » Eos » Version: 4.24.0f
    cpe:2.3:o:arista:eos:4.24.0f
  • Arista » Eos » Version: 4.24.2.1f
    cpe:2.3:o:arista:eos:4.24.2.1f
  • Arista » Eos » Version: 4.24.2.4f
    cpe:2.3:o:arista:eos:4.24.2.4f
  • Arista » Eos » Version: 4.24.2f
    cpe:2.3:o:arista:eos:4.24.2f
  • Arista » Eos » Version: 4.24.3.1m
    cpe:2.3:o:arista:eos:4.24.3.1m
  • Arista » Eos » Version: 4.24.5m
    cpe:2.3:o:arista:eos:4.24.5m
  • Arista » Eos » Version: 4.24.7
    cpe:2.3:o:arista:eos:4.24.7
  • Arista » Eos » Version: 4.24.7m
    cpe:2.3:o:arista:eos:4.24.7m
  • Arista » Eos » Version: 4.25.0
    cpe:2.3:o:arista:eos:4.25.0
  • Arista » Eos » Version: 4.25.0f
    cpe:2.3:o:arista:eos:4.25.0f
  • Arista » Eos » Version: 4.25.1f
    cpe:2.3:o:arista:eos:4.25.1f
  • Arista » Eos » Version: 4.25.2f
    cpe:2.3:o:arista:eos:4.25.2f
  • Arista » Eos » Version: 4.25.4
    cpe:2.3:o:arista:eos:4.25.4
  • Arista » Eos » Version: 4.25.5
    cpe:2.3:o:arista:eos:4.25.5
  • Arista » Eos » Version: 4.25.5.1m
    cpe:2.3:o:arista:eos:4.25.5.1m
  • Arista » Eos » Version: 4.26.0
    cpe:2.3:o:arista:eos:4.26.0
  • Arista » Eos » Version: 4.26.1
    cpe:2.3:o:arista:eos:4.26.1
  • Arista » Eos » Version: 4.26.1f
    cpe:2.3:o:arista:eos:4.26.1f
  • Arista » Eos » Version: 4.26.2
    cpe:2.3:o:arista:eos:4.26.2
  • Arista » Eos » Version: 4.26.2f
    cpe:2.3:o:arista:eos:4.26.2f


Contact Us

Shodan ® - All rights reserved