CVE-2021-28509
This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig transport protocols. The impact of this vulnerability is that, in certain conditions, TerminAttr might leak MACsec sensitive data in clear text in CVP to other authorized users, which could cause MACsec traffic to be decrypted or modified by other authorized users on the device.
Published:May 26, 2022
Last Modified:Nov 21, 2024
EPS:May 26, 2022
EPSS Score:0.00142
CVSS Score:6.1
Affected Products
Vendor
Product
Action
Vendor
Arista
Product
7050cx3-32s
Arista
7050cx3-32s
Vendor
Arista
Product
7050cx3m-32s
Arista
7050cx3m-32s
Vendor
Arista
Product
7050sx3-48c8
Arista
7050sx3-48c8
Vendor
Arista
Product
7050sx3-48yc
Arista
7050sx3-48yc
Vendor
Arista
Product
7050sx3-48yc12
Arista
7050sx3-48yc12
Vendor
Arista
Product
7050sx3-48yc8
Arista
7050sx3-48yc8
Vendor
Arista
Product
7050sx3-96yc8
Arista
7050sx3-96yc8
Vendor
Arista
Product
7050tx3-48c8
Arista
7050tx3-48c8
Vendor
Arista
Product
7280cr2ak-30
Arista
7280cr2ak-30
Vendor
Arista
Product
7280cr2k-60
Arista
7280cr2k-60
Vendor
Arista
Product
7280cr3-32d4
Arista
7280cr3-32d4
Vendor
Arista
Product
7280cr3-32p4
Arista
7280cr3-32p4
Vendor
Arista
Product
7280cr3-96
Arista
7280cr3-96
Vendor
Arista
Product
7280cr3k-32d4
Arista
7280cr3k-32d4
Vendor
Arista
Product
7280cr3k-32p4
Arista
7280cr3k-32p4
Vendor
Arista
Product
7280cr3k-96
Arista
7280cr3k-96
Vendor
Arista
Product
7280dr3-24
Arista
7280dr3-24
Vendor
Arista
Product
7280dr3k-24
Arista
7280dr3k-24
Vendor
Arista
Product
7280pr3-24
Arista
7280pr3-24
Vendor
Arista
Product
7280pr3k-24
Arista
7280pr3k-24
Vendor
Arista
Product
7280r2
Arista
7280r2
Vendor
Arista
Product
7280r3
Arista
7280r3
Vendor
Arista
Product
7280sr3-48yc8
Arista
7280sr3-48yc8
Vendor
Arista
Product
7280sr3k-48yc8
Arista
7280sr3k-48yc8
Vendor
Arista
Product
7388x5
Arista
7388x5
Vendor
Arista
Product
7500r2
Arista
7500r2
Vendor
Arista
Product
7500r3
Arista
7500r3
Vendor
Arista
Product
7500r3-24d
Arista
7500r3-24d
Vendor
Arista
Product
7500r3-24p
Arista
7500r3-24p
Vendor
Arista
Product
7500r3-36cq
Arista
7500r3-36cq
Vendor
Arista
Product
7500r3k-36cq
Arista
7500r3k-36cq
Vendor
Arista
Product
7800r3-36p
Arista
7800r3-36p
Vendor
Arista
Product
7800r3-48cq
Arista
7800r3-48cq
Vendor
Arista
Product
7800r3k-48cq
Arista
7800r3k-48cq
Vendor
Arista
Product
Ccs-722xpm-48y4
Arista
Ccs-722xpm-48y4
Vendor
Arista
Product
Ccs-722xpm-48zy8
Arista
Ccs-722xpm-48zy8
Vendor
Arista
Product
Dcs-7050cx3-32s
Arista
Dcs-7050cx3-32s
Vendor
Arista
Product
Dcs-7050cx3-32s-r
Arista
Dcs-7050cx3-32s-r
Vendor
Arista
Product
Dcs-7050cx3m-32s
Arista
Dcs-7050cx3m-32s
Vendor
Arista
Product
Dcs-7050sx3-48c8
Arista
Dcs-7050sx3-48c8
Vendor
Arista
Product
Dcs-7050sx3-48yc12
Arista
Dcs-7050sx3-48yc12
Vendor
Arista
Product
Dcs-7050sx3-48yc8
Arista
Dcs-7050sx3-48yc8
Vendor
Arista
Product
Dcs-7050sx3-96yc8
Arista
Dcs-7050sx3-96yc8
Vendor
Arista
Product
Eos
Arista
Eos
Vendor
Arista
Product
Terminattr
Arista
Terminattr
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
