CVE-2021-28493: High severity Arista Metamako Operating System vulnerability
Published Sep 9, 2021
·Updated
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, a user may be able to execute commands despite not having the privileges to do so. This issue affects: Arista Metamako Operating System All releases in the MOS-0.1x train MOS-0.32.0 and prior releases
Affected Software
2 affected components
Arista Metamako Operating System<=0.32.0
Arista 7130
Remediation
Information
Upgrade to MOS-0.33.0
Event History
Sep 9, 2021
CVE Published
via MITRE·12:45 PM
Data Sourced
via MITRE·12:45 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2021-28493.
2
What is the severity rating for CVE-2021-28493?
The severity rating for CVE-2021-28493 is 7.8 (high).
3
What is the affected software for CVE-2021-28493?
The affected software for CVE-2021-28493 is Arista Metamako Operating System (all releases in the MOS-0.1x train).
4
How can this vulnerability be exploited?
Under certain conditions, a user may be able to execute commands despite not having the privileges to do so.
5
Is Arista 7130 affected by CVE-2021-28493?
No, Arista 7130 is not affected by CVE-2021-28493.