Database/Firmware, BMC & network fabric

Arista EOS (TerminAttr / IPsec): TerminAttr leaks IPsec sensitive material in plaintext to authorized users
CVSS 7.5CVE-2021-28508Firmware, BMC & network fabriccurated
Impact
TerminAttr leaks IPsec sensitive material in plaintext to authorized users — fabric encryption keys exposed through the telemetry agent
Who can reach it
Local/network
What to do
EOS + TerminAttr upgrade plus rotation of any IPsec keys that were live on the affected switches
References
Related entries
- GRUB2 (PNG reader): A crafted PNG in the boot splash path causes an out-of-bounds write in GRUBCVE-2021-3695 · GRUB2 (PNG reader)High
- GRUB2 (JPEG reader): Crafted JPEG in the boot path drives a heap out-of-bounds write in GRUBCVE-2021-3697 · GRUB2 (JPEG reader)High
- IBM OpenBMC OP920 / OP930 / OP940: An unauthenticated caller retrieves sensitive information from the BMCCVE-2021-38960 · IBM OpenBMC OP920 / OP930 / OP940High
- OpenBMC phosphor-net-ipmid (IPMI LAN+): Sibling finding to the authentication bypass, from the same Google reportCVE-2021-39295 · OpenBMC phosphor-net-ipmid (IPMI LAN+)High
- Linux kernel NVMe-oF RDMA target (nvmet-rdma error completion handling with shared CQ): After the switch to sharedCVE-2021-46983 · Linux kernel NVMe-oF RDMA target (nvmet-rdma error completion handling with shared CQ)High
- AMD SEV-SNP - VM_HSAVE_PA MSR validation: Insufficient validation of the VM_HSAVE_PA model-specific register lets aCVE-2022-23818 · AMD SEV-SNP - VM_HSAVE_PA MSR validationHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.