Database/Firmware, BMC & network fabric

Arista EOS (gNOI): gNOI APIs bypass authentication, allowing an unauthenticated factory reset of the switch
CVSS 9.1CVE-2021-28506Firmware, BMC & network fabriccurated
Impact
gNOI APIs bypass authentication, allowing an unauthenticated factory reset of the switch — instant fabric-wide outage primitive
Who can reach it
Network
What to do
EOS upgrade; interim mitigation is a service ACL restricting gNOI, though CVE-2021-28507 shows those ACLs were themselves bypassable
References
Related entries
- APC Smart-UPS SMT/SMC/SMX/SCL/SMTL series - firmware update signing: Firmware images are signed with a key that leakedCVE-2022-0715 · APC Smart-UPS SMT/SMC/SMX/SCL/SMTL series - firmware update signingCritical
- AMI MegaRAC SPx12/SPx13: Insufficient verification of data authenticity — firmware image signature can be subvertedCVE-2023-28863 · AMI MegaRAC SPx12/SPx13Critical
- CyberPower PowerPanel Enterprise DCIM - remote backup location username field: OS command injection throughCVE-2023-3267 · CyberPower PowerPanel Enterprise DCIM - remote backup location username fieldCritical
- AMI MegaRAC SPx12 (BMC&C): Auth bypass by spoofing the HTTP headerCVE-2023-34329 · AMI MegaRAC SPx12 (BMC&C)Critical
- Arista EOS (secure VXLAN / Tunnelsec agent): After the Tunnelsec agent restarts, traffic that should be encryptedCVE-2024-12378 · Arista EOS (secure VXLAN / Tunnelsec agent)Critical
- Software House iSTAR door controllers (firmware before 6.6.B) and the IP-ACM Ethernet Door Module link: The iSTARCVE-2024-32752 · Software House iSTAR door controllers (firmware before 6.6.B) and the IP-ACM Ethernet Door Module linkCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.