CVE-2021-28494

CRITICAL

Arista Metamako Operating System < 0.34.0 - Unauthenticated Authentication Bypass via Web UI

Title source: llm
STIX 2.1

Description

In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication is bypassed by unprivileged users who are accessing the Web UI. This issue affects: Arista Metamako Operating System MOS-0.34.0 and prior releases

References (1)

Core 1

Scores

CVSS v3 9.6
EPSS 0.0085
EPSS Percentile 53.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H

Details

CWE
CWE-287
Status published
Products (1)
arista/metamako_operating_system < 0.34.0
Published Sep 09, 2021
Tracked Since Feb 18, 2026