High severity7.2NVD Advisory· Published Sep 9, 2021· Updated Jun 17, 2026
CVE-2021-28495
CVE-2021-28495
Description
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authentication can be bypassed when API access is enabled via the JSON-RPC APIs. This issue affects: Arista Metamako Operating System All releases in the MOS-0.1x train MOS-0.13 and post releases in the MOS-0.1x train MOS-0.26.6 and below releases in the MOS-0.2x train MOS-0.31.1 and below releases in the MOS-0.3x train
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:o:arista:metamako_operating_system:*:*:*:*:*:*:*:*Range: >=0.10.0,<=0.13.0
MOS-0.13 and post releases in the MOS-0.1x train, MOS-0.26.6 and below releases in the MOS-0.2x train, MOS-0.31.1 and below releases in the MOS-0.3x train+ 1 more
- (no CPE)range: MOS-0.13 and post releases in the MOS-0.1x train, MOS-0.26.6 and below releases in the MOS-0.2x train, MOS-0.31.1 and below releases in the MOS-0.3x train
- (no CPE)range: MOS-0.13
Patches
Vulnerability mechanics
References
1- www.arista.com/en/support/advisories-notices/security-advisories/12914-security-advisory-66nvdMitigationVendor Advisory
News mentions
0No linked articles in our index yet.