Vulnerabilities > Arista > Metamako Operating System

DATE CVE VULNERABILITY TITLE RISK
2021-09-09 CVE-2021-28498 Insufficiently Protected Credentials vulnerability in Arista Metamako Operating System
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user enable passwords set in clear text could result in unprivileged users getting complete access to the systems.
local
low complexity
arista CWE-522
7.8
2021-09-09 CVE-2021-28499 Insufficiently Protected Credentials vulnerability in Arista Metamako Operating System
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user account passwords set in clear text could leak to users without any password.
local
low complexity
arista CWE-522
2.1
2021-09-09 CVE-2021-28493 Improper Authentication vulnerability in Arista Metamako Operating System
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, a user may be able to execute commands despite not having the privileges to do so.
local
low complexity
arista CWE-287
4.6
2021-09-09 CVE-2021-28494 Improper Authentication vulnerability in Arista Metamako Operating System
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication is bypassed by unprivileged users who are accessing the Web UI.
network
low complexity
arista CWE-287
6.5
2021-09-09 CVE-2021-28495 Improper Authentication vulnerability in Arista Metamako Operating System
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authentication can be bypassed when API access is enabled via the JSON-RPC APIs.
network
arista CWE-287
6.8
2021-09-09 CVE-2021-28497 Unspecified vulnerability in Arista Metamako Operating System
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, the bash shell might be accessible to unprivileged users in situations where they should not have access.
local
low complexity
arista
4.6