Database/Firmware, BMC & network fabric

Arista EOS (gNOI): gNOI APIs bypass authentication, allowing an unauthenticated factory reset of the switch
CVE-2021-28506Firmware, BMC & network fabriccurated
Impact
gNOI APIs bypass authentication, allowing an unauthenticated factory reset of the switch — instant fabric-wide outage primitive
Who can reach it
Network
What to do
EOS upgrade; interim mitigation is a service ACL restricting gNOI, though CVE-2021-28507 shows those ACLs were themselves bypassable
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.