CVE-2021-28509 is an internally discovered vulnerability in Arista EOS TerminAttr and OpenConfig transport protocols, affecting Arista products. Under specific conditions, this flaw can lead to the cleartext leakage of MACsec sensitive data to other authorized users within CVP. With a CVSS score of 6.1 (Medium), the vulnerability has a network attack vector, low attack complexity, and high impact on confidentiality and integrity, potentially allowing MACsec traffic decryption or modification. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.10.11CPE matchmatch criteria | cpe:2.3:a:arista:terminattr:*:*:*:*:*:*:*:* | ||
>= 1.11.0, < 1.16.8CPE matchmatch criteria | cpe:2.3:a:arista:terminattr:*:*:*:*:*:*:*:* | ||
>= 1.17.0, < 1.19.2CPE matchmatch criteria | cpe:2.3:a:arista:terminattr:*:*:*:*:*:*:*:* | ||
>= 4.23, <= 4.23.11CPE matchmatch criteria | cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* | ||
>= 4.24, < 4.24.10CPE matchmatch criteria | cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.