An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a factory reset of the device.
2022-01-14T20:15:10.327
2024-11-21T05:59:48.060
Modified
CVSSv3.1: 9.1 (CRITICAL)
AV:N/AC:L/Au:N/C:N/I:C/A:C
10.0
9.2
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | arista | eos | ≤ 4.24.7m | Yes |
Operating System | arista | eos | ≤ 4.25.3 | Yes |
Operating System | arista | eos | ≤ 4.25.4m | Yes |
Operating System | arista | eos | ≤ 4.25.5.1m | Yes |
Operating System | arista | eos | ≤ 4.26.2f | Yes |