MEDIUM · 5.3

CVE-2021-28510

For certain systems running EOS, a Precision Time Protocol (PTP) packet of a management/signaling message with an invalid Type-Length-Value (TLV) causes the PTP agent to restart. Repeated restarts of ...

Vulnerability Description

For certain systems running EOS, a Precision Time Protocol (PTP) packet of a management/signaling message with an invalid Type-Length-Value (TLV) causes the PTP agent to restart. Repeated restarts of the service will make the service unavailable.

CVSS Score

5.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
LOW

Affected Products

VendorProductVersions
AristaEos< 4.23.10
Arista7020R-
Arista7050Cx3-32S-
Arista7050Cx3M-32S-
Arista7050Qx-32S-
Arista7050Qx2-32S-
Arista7050Sx-128-
Arista7050Sx-64-
Arista7050Sx-72Q-
Arista7050Sx2-128-
Arista7050Sx2-72Q-
Arista7050Sx3-48C8-
Arista7050Sx3-48Yc-
Arista7050Sx3-48Yc12-
Arista7050Sx3-48Yc8-
Arista7050Sx3-96Yc8-
Arista7050Tx-48-
Arista7050Tx-64-
Arista7050Tx-72Q-
Arista7050Tx2-128-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-28510?

CVE-2021-28510 is a vulnerability with a CVSS score of 5.3 (MEDIUM). For certain systems running EOS, a Precision Time Protocol (PTP) packet of a management/signaling message with an invalid Type-Length-Value (TLV) causes the PTP agent to restart. Repeated restarts of ...

How severe is CVE-2021-28510?

CVE-2021-28510 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-28510?

Check the references section above for vendor advisories and patch information. Affected products include: Arista Eos, Arista 7020R, Arista 7050Cx3-32S, Arista 7050Cx3M-32S, Arista 7050Qx-32S.