CVE-2021-28511
Summary
| CVE | CVE-2021-28511 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-08-05 17:15:00 UTC |
| Updated | 2022-08-15 20:50:00 UTC |
| Description | This advisory documents the impact of an internally found vulnerability in Arista EOS for security ACL bypass. The impact of this vulnerability is that the security ACL drop rule might be bypassed if a NAT ACL rule filter with permit action matches the packet flow. This could allow a host with an IP address in a range that matches the range allowed by a NAT ACL and a range denied by a Security ACL to be forwarded incorrectly as it should have been denied by the Security ACL. This can enable an ACL bypass. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Arista | 7050cx3-32s | - | All | All | All |
| Hardware | Arista | 7050cx3m-32s | - | All | All | All |
| Hardware | Arista | 7050sx3-48c8 | - | All | All | All |
| Hardware | Arista | 7050sx3-48yc | - | All | All | All |
| Hardware | Arista | 7050sx3-48yc12 | - | All | All | All |
| Hardware | Arista | 7050sx3-48yc8 | - | All | All | All |
| Hardware | Arista | 7050sx3-96yc8 | - | All | All | All |
| Hardware | Arista | 7050tx3-48c8 | - | All | All | All |
| Hardware | Arista | 720xp-24y6 | - | All | All | All |
| Hardware | Arista | 720xp-24zy4 | - | All | All | All |
| Hardware | Arista | 720xp-48y6 | - | All | All | All |
| Hardware | Arista | 720xp-48zc2 | - | All | All | All |
| Hardware | Arista | 720xp-96zc2 | - | All | All | All |
| Hardware | Arista | 7300x3-32c | - | All | All | All |
| Hardware | Arista | 7300x3-48yc4 | - | All | All | All |
| Operating System | Arista | Eos | All | All | All | All |
| Operating System | Arista | Eos | All | All | All | All |
| Operating System | Arista | Eos | All | All | All | All |
| Operating System | Arista | Eos | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory 0078 - Arista | MISC | www.arista.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 44004 Arista EOS Improper Access Control Vulnerability (SA0078)