#VU109301 Improper access control in Arista Extensible Operating System (EOS) - CVE-2021-28505
Published: May 17, 2025
Arista Extensible Operating System (EOS)
Arista Networks
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. If a VXLAN match rule exists in an IPv4 access-list that is applied to the ingress of an L2 or an L3 port/SVI, the VXLAN rule and subsequent ACL rules in that access list will ignore the specified IP protocol. A remote attacker can bypass implemented security restrictions and gain unauthorized access to the application.