The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate based authentication is used, which allows remote attackers to access the device via eAPI.
2022-02-04T23:15:11.350
2024-11-21T05:59:47.697
Modified
CVSSv3.1: 7.4 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | arista | eos | ≤ 4.22.9m | Yes |
| Operating System | arista | eos | ≤ 4.23.9 | Yes |
| Operating System | arista | eos | ≤ 4.24.7 | Yes |
| Operating System | arista | eos | ≤ 4.25.5 | Yes |
| Operating System | arista | eos | ≤ 4.26.2 | Yes |