CVE-2021-28495
09.09.2021, 13:15
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authentication can be bypassed when API access is enabled via the JSON-RPC APIs. This issue affects: Arista Metamako Operating System All releases in the MOS-0.1x train MOS-0.13 and post releases in the MOS-0.1x train MOS-0.26.6 and below releases in the MOS-0.2x train MOS-0.31.1 and below releases in the MOS-0.3x trainEnginsight
Vendor | Product | Version |
---|---|---|
arista | metamako_operating_system | 0.10.0 ≤ 𝑥 ≤ 0.13.0 |
arista | metamako_operating_system | 0.20.0 ≤ 𝑥 ≤ 0.26.7 |
arista | metamako_operating_system | 0.30.0 ≤ 𝑥 < 0.32.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration