CVE-2021-28495

HIGH

Arista Metamako OS <=0.26.6, 0.31.1 - Unauthenticated Auth Bypass via JSON-RPC API

Title source: llm
STIX 2.1

Description

In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authentication can be bypassed when API access is enabled via the JSON-RPC APIs. This issue affects: Arista Metamako Operating System All releases in the MOS-0.1x train MOS-0.13 and post releases in the MOS-0.1x train MOS-0.26.6 and below releases in the MOS-0.2x train MOS-0.31.1 and below releases in the MOS-0.3x train

References (1)

Core 1

Scores

CVSS v3 7.2
EPSS 0.0090
EPSS Percentile 55.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L

Details

CWE
CWE-287
Status published
Products (1)
arista/metamako_operating_system 0.10.0 - 0.13.0
Published Sep 09, 2021
Tracked Since Feb 18, 2026