Medium severity5.5NVD Advisory· Published Jan 14, 2022· Updated Jun 17, 2026
CVE-2021-28507
CVE-2021-28507
Description
An issue has recently been discovered in Arista EOS where, under certain conditions, the service ACL configured for OpenConfig gNOI and OpenConfig RESTCONF might be bypassed, which results in the denied requests being forwarded to the agent.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*range: >=4.23.0,<=4.23.9m
- cpe:2.3:o:arista:eos:4.21.0f:*:*:*:*:*:*:*
- cpe:2.3:o:arista:eos:4.21.1f:*:*:*:*:*:*:*
- cpe:2.3:o:arista:eos:4.21.3f:*:*:*:*:*:*:*
- cpe:2.3:o:arista:eos:4.22.0f:*:*:*:*:*:*:*
- cpe:2.3:o:arista:eos:4.22.1f:*:*:*:*:*:*:*
- (no CPE)
- Arista Networks/EOSv5Range: 4.22.x
Patches
Vulnerability mechanics
References
1- www.arista.com/en/support/advisories-notices/security-advisories/13449-security-advisory-0071nvdExploitMitigationPatchVendor Advisory
News mentions
0No linked articles in our index yet.