Database/Firmware, BMC & network fabric

Arista EOS (eAPI certificate auth): Certificate-based eAPI authentication skips credential re-evaluation
CVSS 9.8CVE-2021-28503Firmware, BMC & network fabriccurated
Impact
Certificate-based eAPI authentication skips credential re-evaluation — authentication bypass on the switch's programmatic API, which is exactly the interface a neocloud's fabric automation uses
Who can reach it
Network
What to do
EOS upgrade with fabric failover; also rotate any eAPI client certificates issued while vulnerable
References
Related entries
- HPE iLO Amplifier Pack (unauthenticated directory traversal): Unauthenticated directory traversal on the iLO AmplifierCVE-2021-29212 · HPE iLO Amplifier Pack (unauthenticated directory traversal)Critical
- Insyde InsydeH2O (AtaLegacySmm SMM driver): The SMI handler in the legacy ATA driver does not validate the CommBufferCVE-2021-41842 · Insyde InsydeH2O (AtaLegacySmm SMM driver)Critical
- ArubaOS-Switch (HPE Aruba wired switches): Remote arbitrary code execution on ArubaOS-Switch devices, affectingCVE-2022-23676 · ArubaOS-Switch (HPE Aruba wired switches)Critical
- coreboot 4.13-4.16 (SMM handling on application processors): Arbitrary code execution in System Management ModeCVE-2022-29264 · coreboot 4.13-4.16 (SMM handling on application processors)Critical
- Ampere Altra and Altra Max UEFI reference design before SRP 1.09 - SMC interface exposing SPI-NOR flash: The OSCVE-2022-32295 · Ampere Altra and Altra Max UEFI reference design before SRP 1.09 - SMC interface exposing SPI-NOR flashCritical
- APC Easy UPS Online Monitoring Software (Windows and Windows Server): Critical functions in the UPS monitoring serverCVE-2022-42970 · APC Easy UPS Online Monitoring Software (Windows and Windows Server)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.