In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authentication can be bypassed when API access is enabled via the JSON-RPC APIs. This issue affects: Arista Metamako Operating System All releases in the MOS-0.1x train MOS-0.13 and post releases in the MOS-0.1x train MOS-0.26.6 and below releases in the MOS-0.2x train MOS-0.31.1 and below releases in the MOS-0.3x train
2021-09-09T13:15:09.103
2024-11-21T05:59:46.757
Modified
CVSSv3.1: 7.2 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | arista | metamako_operating_system | ≤ 0.13.0 | Yes |
| Operating System | arista | metamako_operating_system | ≤ 0.26.7 | Yes |
| Operating System | arista | metamako_operating_system | < 0.32.0 | Yes |
| Hardware | arista | 7130 | - | No |