VYPR
Medium severity5.5NVD Advisory· Published Jan 14, 2022· Updated Jun 17, 2026

CVE-2021-28507

CVE-2021-28507

Description

An issue has recently been discovered in Arista EOS where, under certain conditions, the service ACL configured for OpenConfig gNOI and OpenConfig RESTCONF might be bypassed, which results in the denied requests being forwarded to the agent.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • Arista/Eos7 versions
    cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*range: >=4.23.0,<=4.23.9m
    • cpe:2.3:o:arista:eos:4.21.0f:*:*:*:*:*:*:*
    • cpe:2.3:o:arista:eos:4.21.1f:*:*:*:*:*:*:*
    • cpe:2.3:o:arista:eos:4.21.3f:*:*:*:*:*:*:*
    • cpe:2.3:o:arista:eos:4.22.0f:*:*:*:*:*:*:*
    • cpe:2.3:o:arista:eos:4.22.1f:*:*:*:*:*:*:*
    • (no CPE)
  • Arista Networks/EOSv5
    Range: 4.22.x

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.