Vulnerability Description
On affected Arista EOS platforms, if a VXLAN match rule exists in an IPv4 access-list that is applied to the ingress of an L2 or an L3 port/SVI, the VXLAN rule and subsequent ACL rules in that access list will ignore the specified IP protocol.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Arista | Eos | >= 4.26, < 4.26.4m |
| Arista | Ccs-710P-12 | - |
| Arista | Ccs-710P-16P | - |
| Arista | Ccs-720Xp-24Y6 | - |
| Arista | Ccs-720Xp-24Zy4 | - |
| Arista | Ccs-720Xp-48Y6 | - |
| Arista | Ccs-720Xp-48Zc2 | - |
| Arista | Ccs-720Xp-96Zc2 | - |
| Arista | Ccs-722Xpm-48Y4 | - |
| Arista | Ccs-722Xpm-48Zy8 | - |
| Arista | Dcs-7010Tx-48 | - |
| Arista | Dcs-7050Cx3-32S | - |
| Arista | Dcs-7050Cx3M-32S | - |
| Arista | Dcs-7050Sx3-48C8 | - |
| Arista | Dcs-7050Sx3-48Yc12 | - |
| Arista | Dcs-7050Sx3-48Yc8 | - |
| Arista | Dcs-7050Sx3-96Yc8 | - |
| Arista | Dcs-7050Tx3-48C8 | - |
Related Weaknesses (CWE)
References
- https://www.arista.com/en/support/advisories-notices/security-advisories/15267-sExploitVendor Advisory
- https://www.arista.com/en/support/advisories-notices/security-advisories/15267-sExploitVendor Advisory
FAQ
What is CVE-2021-28505?
CVE-2021-28505 is a vulnerability with a CVSS score of 7.5 (HIGH). On affected Arista EOS platforms, if a VXLAN match rule exists in an IPv4 access-list that is applied to the ingress of an L2 or an L3 port/SVI, the VXLAN rule and subsequent ACL rules in that access ...
How severe is CVE-2021-28505?
CVE-2021-28505 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-28505?
Check the references section above for vendor advisories and patch information. Affected products include: Arista Eos, Arista Ccs-710P-12, Arista Ccs-710P-16P, Arista Ccs-720Xp-24Y6, Arista Ccs-720Xp-24Zy4.