CVE detail

CVE-2021-28508 — CVE-2021-28508

Published 2022-05-26 · Modified 2026-06-17 · Vendor arista · Product terminattr · Source nvd
MEDIUM
severity
CVSS-derived band
6.8
CVSS v3
0–10 scale
0.0049
EPSS probability
exploitation probability, 30d
40.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog

Description

This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig transport protocols. The impact of this vulnerability is that, in certain conditions, TerminAttr might leak IPsec sensitive data in clear text in CVP to other authorized users, which could cause IPsec traffic to be decrypted or modified by other authorized users on the device.

Remediation

vendor remediation guidance

The recommended resolution is to upgrade to a remediated software version at your earliest convenience. The vulnerability is fixed in the following versions: EOS versions: 4.24.10 and later release in the 4.24.x train 4.25.8 and later releases in the 4.25.x train 4.26.6 and later releases in the 4.26.x train 4.27.2 and later releases in the 4.27.x train TerminAttr versions: TerminAttr v1.10.11 and later releases in the v1.10.x train TerminAttr v1.16.8 and later releases in the v1.16.x train TerminAttr v1.19.0 and later releases

workarounds

On the affected versions, the vulnerabilities can be mitigated by disabling TerminAttr agent.

ProductVulnerable rangeFixed versionAdvisory
Arista Networks Arista EOS>=4.23<=4.23.114.23.11advisory ↗
Arista Networks Arista EOS>=4.24<=4.24.94.24.9advisory ↗
Arista Networks Arista EOS>=4.25<=4.25.74.25.7advisory ↗
Arista Networks Arista EOS>=4.26<=4.26.54.26.5advisory ↗
Arista Networks Arista EOS>=4.27<=4.27.34.27.3advisory ↗
Arista Networks Arista TerminAttr>=v1.10<=v1.10.10v1.10.10advisory ↗
Arista Networks Arista TerminAttr>=v1.16<=v1.16.7v1.16.7advisory ↗
Arista Networks Arista TerminAttr>=v1.18<=v1.18.1v1.18.1advisory ↗

References

cvedb.io · NVD · CISA KEV · FIRST EPSS · vendor advisories (CVE Program List v5). Informational only, no warranty — verify every remediation against the vendor advisory before acting on it. This product uses data from the NVD API but is not endorsed or certified by the NVD, CISA, FIRST.org or any vendor named. CVE® is a registered trademark of The MITRE Corporation.