Vulnerabilities > Arista > EOS > 4.26.2f
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-01-14 | CVE-2021-28506 | Missing Authorization vulnerability in Arista EOS An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a factory reset of the device. | 9.1 |
2022-01-14 | CVE-2021-28507 | Unspecified vulnerability in Arista EOS An issue has recently been discovered in Arista EOS where, under certain conditions, the service ACL configured for OpenConfig gNOI and OpenConfig RESTCONF might be bypassed, which results in the denied requests being forwarded to the agent. | 7.1 |