On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which matches on “vxlan” as protocol then that rule and subsequent rules ( rules declared after it in ACL ) do not match on IP protocol field as expected.
References
Link | Resource |
---|---|
https://www.arista.com/en/support/advisories-notices/security-advisories/15267-security-advisory-0073 | Mitigation Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2022-04-01 16:15
Updated : 2022-04-12 06:25
NVD link : CVE-2021-28504
Mitre link : CVE-2021-28504
JSON object : View
CWE
CWE-863
Incorrect Authorization
Products Affected
arista
- ccs-720xp-24zy4
- ccs-710p-12
- dcs-7050tx3-48c8
- ccs-720xp-96zc2
- dcs-7050sx3-48yc8
- dcs-7010tx-48
- dcs-7050cx3m-32s
- dcs-7050sx3-96yc8
- eos
- ccs-720xp-48zc2
- dcs-7050cx3-32s
- ccs-720xp-48y6
- ccs-722xpm-48zy8
- ccs-710p-16p
- dcs-7050sx3-48c8
- ccs-720xp-24y6
- ccs-722xpm-48y4
- dcs-7050sx3-48yc12