Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2021-28505 Details
Description
On affected Arista EOS platforms, if a VXLAN match rule exists in an IPv4 access-list that is applied to the ingress of an L2 or an L3 port/SVI, the VXLAN rule and subsequent ACL rules in that access list will ignore the specified IP protocol.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.arista.com/en/support/advisories-notices/security-advisories/15267-security-advisory-0073 | CVE | ExploitVendor Advisory |
| https://www.arista.com/en/support/advisories-notices/security-advisories/15267-security-advisory-0073 | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| arista eos | >= 4.26, < 4.26.4m >= 4.27, < 4.27.1f |
CPE
Remediation
| |
| arista ccs-710p-12 | All versions |
CPE
Remediation
| |
| arista ccs-710p-16p | All versions |
CPE
Remediation
| |
| arista ccs-720xp-24y6 | All versions |
CPE
Remediation
| |
| arista ccs-720xp-24zy4 | All versions |
CPE
Remediation
| |
| arista ccs-720xp-48y6 | All versions |
CPE
Remediation
| |
| arista ccs-720xp-48zc2 | All versions |
CPE
Remediation
| |
| arista ccs-720xp-96zc2 | All versions |
CPE
Remediation
| |
| arista ccs-722xpm-48y4 | All versions |
CPE
Remediation
| |
| arista ccs-722xpm-48zy8 | All versions |
CPE
Remediation
| |
| arista dcs-7010tx-48 | All versions |
CPE
Remediation
| |
| arista dcs-7050cx3-32s | All versions |
CPE
Remediation
| |
| arista dcs-7050cx3m-32s | All versions |
CPE
Remediation
| |
| arista dcs-7050sx3-48c8 | All versions |
CPE
Remediation
| |
| arista dcs-7050sx3-48yc12 | All versions |
CPE
Remediation
| |
| arista dcs-7050sx3-48yc8 | All versions |
CPE
Remediation
| |
| arista dcs-7050sx3-96yc8 | All versions |
CPE
Remediation
| |
| arista dcs-7050tx3-48c8 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Apr 26, 2022 | Initial Analysis | [email protected] |