
CVE-2021-28506 – An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a factory reset of the device.
https://notcve.org/view.php?id=CVE-2021-28506
14 Jan 2022 — An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a factory reset of the device. Se ha detectado recientemente un problema en Arista EOS donde determinadas API de gNOI omiten incorrectamente la autorización y la autenticación, lo que podría permitir un restablecimiento de fábrica del dispositivo • https://www.arista.com/en/support/advisories-notices/security-advisories/13449-security-advisory-0071 • CWE-285: Improper Authorization CWE-306: Missing Authentication for Critical Function CWE-862: Missing Authorization •

CVE-2021-28496 – In Arista's EOS software affected releases, the shared secret profiles sensitive configuration might be leaked when displaying output over eAPI or other JSON outputs to authenticated users on the device.
https://notcve.org/view.php?id=CVE-2021-28496
21 Oct 2021 — On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the password configured for use by BiDirectional Forwarding Detection (BFD) will be leaked when displaying output over eAPI or other JSON outputs to other authenticated users on the device. The affected EOS Versions are: all releases in 4.22.x train, 4.23.9 and below releases in the 4.23.x train, 4.24.7 and below releases in the 4.24.x train, 4.25.4 and below releases in the 4.25.x train, 4.26.1 a... • https://www.arista.com/en/support/advisories-notices/security-advisories/13243-security-advisory-0069 • CWE-311: Missing Encryption of Sensitive Data CWE-522: Insufficiently Protected Credentials •

CVE-2020-25684 – dnsmasq: loose address/port check in reply_query() makes forging replies easier for an off-path attacker
https://notcve.org/view.php?id=CVE-2020-25684
19 Jan 2021 — A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in the forward.c:reply_query() if the reply destination address/port is used by the pending forwarded queries. However, it does not use the address/port to retrieve the exact forwarded query, substantially reducing the number of attempts an attacker on the network would have to perform to forge a reply and get it accepted by dnsmasq. This issue contrasts with RFC5452, which specifies a query's attrib... • https://bugzilla.redhat.com/show_bug.cgi?id=1889686 • CWE-358: Improperly Implemented Security Check for Standard •

CVE-2020-25685 – dnsmasq: loose query name check in reply_query() makes forging replies easier for an off-path attacker
https://notcve.org/view.php?id=CVE-2020-25685
19 Jan 2021 — A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in forward.c:reply_query(), which is the forwarded query that matches the reply, by only using a weak hash of the query name. Due to the weak hash (CRC32 when dnsmasq is compiled without DNSSEC, SHA-1 when it is) this flaw allows an off-path attacker to find several different domains all having the same hash, substantially reducing the number of attempts they would have to perform to forge a reply an... • https://bugzilla.redhat.com/show_bug.cgi?id=1889688 • CWE-326: Inadequate Encryption Strength •

CVE-2020-25686 – dnsmasq: multiple queries forwarded for the same name makes forging replies easier for an off-path attacker
https://notcve.org/view.php?id=CVE-2020-25686
19 Jan 2021 — A flaw was found in dnsmasq before version 2.83. When receiving a query, dnsmasq does not check for an existing pending request for the same name and forwards a new request. By default, a maximum of 150 pending queries can be sent to upstream servers, so there can be at most 150 queries for the same name. This flaw allows an off-path attacker on the network to substantially reduce the number of attempts that it would have to perform to forge a reply and have it accepted by dnsmasq. This issue is mentioned i... • https://github.com/knqyf263/dnspooq • CWE-290: Authentication Bypass by Spoofing CWE-358: Improperly Implemented Security Check for Standard •