In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authentication can be bypassed when API access is enabled via the JSON-RPC APIs. This issue affects: Arista Metamako Operating System All releases in the MOS-0.1x train MOS-0.13 and post releases in the MOS-0.1x train MOS-0.26.6 and below releases in the MOS-0.2x train MOS-0.31.1 and below releases in the MOS-0.3x train
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published: 2021-09-09T12:43:57

Updated: 2024-08-03T21:47:32.686Z

Reserved: 2021-03-16T00:00:00

Link: CVE-2021-28495

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-09-09T13:15:09.103

Modified: 2021-09-22T16:34:39.700

Link: CVE-2021-28495

cve-icon Redhat

No data.