Database/Firmware, BMC & network fabric

Arista EOS (eAPI certificate auth): Certificate-based eAPI authentication skips credential re-evaluation
CVE-2021-28503Firmware, BMC & network fabriccurated
Impact
Certificate-based eAPI authentication skips credential re-evaluation — authentication bypass on the switch's programmatic API, which is exactly the interface a neocloud's fabric automation uses
Who can reach it
Network
What to do
EOS upgrade with fabric failover; also rotate any eAPI client certificates issued while vulnerable
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.