- Description
- In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authentication can be bypassed when API access is enabled via the JSON-RPC APIs. This issue affects: Arista Metamako Operating System All releases in the MOS-0.1x train MOS-0.13 and post releases in the MOS-0.1x train MOS-0.26.6 and below releases in the MOS-0.2x train MOS-0.31.1 and below releases in the MOS-0.3x train
- Source
- psirt@arista.com
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 2.0
- Type
- Primary
- Base score
- 6.8
- Impact score
- 6.4
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:P
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:arista:7130:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4D832798-DA45-4F9E-AA31-5D088253A28A"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:arista:metamako_operating_system:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6B89974C-FC70-4BA1-B700-2F0E1A448939",
"versionEndIncluding": "0.13.0",
"versionStartIncluding": "0.10.0"
},
{
"criteria": "cpe:2.3:o:arista:metamako_operating_system:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A83336C6-BEDD-4A4B-8A4D-D230274BC9BC",
"versionEndIncluding": "0.26.7",
"versionStartIncluding": "0.20.0"
},
{
"criteria": "cpe:2.3:o:arista:metamako_operating_system:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "679CE6C2-27E1-4C2C-BF0C-51B158870F6B",
"versionEndExcluding": "0.32.0",
"versionStartIncluding": "0.30.0"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
]