The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate based authentication is used, which allows remote attackers to access the device via eAPI.
| Software | From | Fixed in |
|---|---|---|
| arista / eos | 4.24 | 4.24.7.x |
| arista / eos | 4.23 | 4.23.9.x |
| arista / eos | 4.26 | 4.26.2.x |
| arista / eos | 4.25 | 4.25.5.x |
| arista / eos | 4.22 | 4.22.9m.x |