HIGH · 7.5

CVE-2021-28504

On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which matches on “vxlan” as protocol then that rule and subsequent rules ( rules declar...

Vulnerability Description

On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which matches on “vxlan” as protocol then that rule and subsequent rules ( rules declared after it in ACL ) do not match on IP protocol field as expected.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
AristaEos>= 4.26, < 4.26.4m
AristaCcs-710P-12-
AristaCcs-710P-16P-
AristaCcs-720Xp-24Y6-
AristaCcs-720Xp-24Zy4-
AristaCcs-720Xp-48Y6-
AristaCcs-720Xp-48Zc2-
AristaCcs-720Xp-96Zc2-
AristaCcs-722Xpm-48Y4-
AristaCcs-722Xpm-48Zy8-
AristaDcs-7010Tx-48-
AristaDcs-7050Cx3-32S-
AristaDcs-7050Cx3M-32S-
AristaDcs-7050Sx3-48C8-
AristaDcs-7050Sx3-48Yc12-
AristaDcs-7050Sx3-48Yc8-
AristaDcs-7050Sx3-96Yc8-
AristaDcs-7050Tx3-48C8-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-28504?

CVE-2021-28504 is a vulnerability with a CVSS score of 7.5 (HIGH). On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which matches on “vxlan” as protocol then that rule and subsequent rules ( rules declar...

How severe is CVE-2021-28504?

CVE-2021-28504 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-28504?

Check the references section above for vendor advisories and patch information. Affected products include: Arista Eos, Arista Ccs-710P-12, Arista Ccs-710P-16P, Arista Ccs-720Xp-24Y6, Arista Ccs-720Xp-24Zy4.