Database/Firmware, BMC & network fabric

Arista EOS (service ACLs): Service ACL bypass for OpenConfig gNOI and RESTCONF
CVSS 7.1CVE-2021-28507Firmware, BMC & network fabriccurated
Impact
Service ACL bypass for OpenConfig gNOI and RESTCONF — the compensating control for the above does not hold
Who can reach it
Network
What to do
EOS upgrade; important because it invalidates "we ACL'd the management API" as a mitigation
References
Related entries
- Dell Enterprise SONiC OS (information disclosure): An authenticated user can extract sensitive informationCVE-2021-36309 · Dell Enterprise SONiC OS (information disclosure)High
- Linux kernel (drivers/infiniband/sw/siw): A tenant gets an out-of-bounds kernel array read using values it controls.CVE-2022-50736 · Linux kernel (drivers/infiniband/sw/siw)High
- AMD Secure Processor - hardware config integrity across power save/restore: Hardware configuration state is notCVE-2023-31316 · AMD Secure Processor - hardware config integrity across power save/restoreHigh
- AMI MegaRAC SPx (BMC TLS certificate / cryptographic keys): A hard-coded certificate and its private key ship insideCVE-2023-34338 · AMI MegaRAC SPx (BMC TLS certificate / cryptographic keys)High
- Intel TDX module: Insufficient control-flow management in the TDX module lets a privileged host user deny serviceCVE-2024-21801 · Intel TDX moduleHigh
- SEV-ES / SEV-SNP guest kernel - injection of virtual interrupts 0 and 14: An untrusted hypervisor can inject virtualCVE-2024-25743 · SEV-ES / SEV-SNP guest kernel - injection of virtual interrupts 0 and 14High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.