漏洞标题
运行配置了 OpenConfig 的 Arista EOS 的受影响平台上,本应被拒绝的 gNOI 请求可以被运行
漏洞描述信息
在运行配置了OpenConfig的Arista EOS的操作平台上,一个应被拒绝的gNOI请求可以被执行。此问题可能导致用户获取不应访问的数据。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
漏洞类别
跨界内存读
漏洞标题
On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected.
漏洞描述信息
On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result in users retrieving data that should not have been available
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
漏洞类别
访问控制不恰当