CVE-2021-28493

HIGH

Arista Metamako Operating System < 0.32.0 - Improper Authentication

Title source: llm
STIX 2.1

Description

In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, a user may be able to execute commands despite not having the privileges to do so. This issue affects: Arista Metamako Operating System All releases in the MOS-0.1x train MOS-0.32.0 and prior releases

References (1)

Core 1

Scores

CVSS v3 8.4
EPSS 0.0021
EPSS Percentile 11.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H

Details

CWE
CWE-287
Status published
Products (1)
arista/metamako_operating_system < 0.32.0
Published Sep 09, 2021
Tracked Since Feb 18, 2026