Vulnerabilities > Arista

DATE CVE VULNERABILITY TITLE RISK
2021-09-09 CVE-2021-28494 Improper Authentication vulnerability in Arista Metamako Operating System
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication is bypassed by unprivileged users who are accessing the Web UI.
network
low complexity
arista CWE-287
8.8
2021-09-09 CVE-2021-28495 Improper Authentication vulnerability in Arista Metamako Operating System
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authentication can be bypassed when API access is enabled via the JSON-RPC APIs.
network
low complexity
arista CWE-287
critical
9.8
2021-09-09 CVE-2021-28497 Unspecified vulnerability in Arista Metamako Operating System
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, the bash shell might be accessible to unprivileged users in situations where they should not have access.
local
low complexity
arista
7.8
2021-05-11 CVE-2020-24586 The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that received fragments be cleared from memory after (re)connecting to a network.
low complexity
ieee debian linux arista intel
3.5
2021-05-11 CVE-2020-24587 Use of a Broken or Risky Cryptographic Algorithm vulnerability in multiple products
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key.
2.6
2021-05-11 CVE-2020-24588 Use of a Broken or Risky Cryptographic Algorithm vulnerability in multiple products
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated.
3.5
2021-05-11 CVE-2020-26139 Improper Authentication vulnerability in multiple products
An issue was discovered in the kernel in NetBSD 7.1.
5.3
2021-05-11 CVE-2020-26140 Use of a Broken or Risky Cryptographic Algorithm vulnerability in multiple products
An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H.
6.5
2021-05-11 CVE-2020-26143 Improper Input Validation vulnerability in multiple products
An issue was discovered in the ALFA Windows 10 driver 1030.36.604 for AWUS036ACH.
low complexity
alfa arista siemens CWE-20
6.5
2021-05-11 CVE-2020-26144 Improper Input Validation vulnerability in multiple products
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices.
low complexity
samsung arista siemens CWE-20
6.5