← Back

CVE-2021-28495

nvd nist
Published: Sep 9, 2021Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authentication can be bypassed when API access is enabled via the JSON-RPC APIs. This issue affects: Arista Metamako Operating System All releases in the MOS-0.1x train MOS-0.13 and post releases in the MOS-0.1x train MOS-0.26.6 and below releases in the MOS-0.2x train MOS-0.31.1 and below releases in the MOS-0.3x train

Affected (3)

1 product
Metamako Operating System
Configuration A
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Arista
From 0.10.0 to 0.13.0
From 0.20.0 to 0.26.7
From 0.30.0 to 0.32.0
Running on/withPlatform Versions
Arista
7130
All versions

References (2)

Timeline

No history available yet.