Database/Firmware, BMC & network fabric

Arista EOS (TerminAttr AAA): TerminAttr streaming-telemetry agent bypasses AAA, giving unauthorized local device access
CVSS 7.8CVE-2021-28501Firmware, BMC & network fabriccurated
Impact
TerminAttr streaming-telemetry agent bypasses AAA, giving unauthorized local device access — TerminAttr is the CloudVision telemetry agent running on essentially every Arista switch in a managed fabric
Who can reach it
Local
What to do
EOS + TerminAttr upgrade across the fabric
References
Related entries
- BIOS Authenticated Code Module (ACM) for a broad set of Intel processors, including Xeon Scalable: Improper accessCVE-2021-33123 · BIOS Authenticated Code Module (ACM) for a broad set of Intel processors, including Xeon ScalableHigh
- ASPEED LPC control driver (drivers/soc/aspeed/aspeed-lpc-ctrl.c) in the OpenBMC kernel: A process on the BMC that canCVE-2021-42252 · ASPEED LPC control driver (drivers/soc/aspeed/aspeed-lpc-ctrl.c) in the OpenBMC kernelHigh
- AMD Secure Processor (ASP) firmware system-call interface: The ASP firmware does not validate addresses passed acrossCVE-2021-46771 · AMD Secure Processor (ASP) firmware system-call interfaceHigh
- Linux kernel (drivers/infiniband/sw/siw): Soft-iWARP memory-region allocation stores the memory object into the MR andCVE-2021-47012 · Linux kernel (drivers/infiniband/sw/siw)High
- Linux kernel (drivers/infiniband/sw/rxe): When soft-RoCE queue-pair initialisation fails, the QP structure is left fullCVE-2021-47078 · Linux kernel (drivers/infiniband/sw/rxe)High
- Linux kernel (drivers/infiniband/core): The core set the send and receive completion-queue pointers on a queue pairCVE-2021-47196 · Linux kernel (drivers/infiniband/core)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.