Database/Firmware, BMC & network fabric

Arista EOS (TerminAttr / IPsec): TerminAttr leaks IPsec sensitive material in plaintext to authorized users
CVE-2021-28508Firmware, BMC & network fabriccurated
Impact
TerminAttr leaks IPsec sensitive material in plaintext to authorized users — fabric encryption keys exposed through the telemetry agent
Who can reach it
Local/network
What to do
EOS + TerminAttr upgrade plus rotation of any IPsec keys that were live on the affected switches
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.