// For flags

CVE-2021-28498

 

Severity Score

7.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user enable passwords set in clear text could result in unprivileged users getting complete access to the systems. This issue affects: Arista Metamako Operating System MOS-0.13 and post releases in the MOS-0.1x train MOS-0.26.6 and prior releases in the MOS-0.2x train MOS-0.31.1 and prior releases in the MOS-0.3x train

En el software MOS (Metamako Operating System) de Arista, compatible con la línea de productos 7130, las contraseñas de habilitación de usuarios ajustadas en texto sin cifrar podrían resultar en que usuarios no privilegiados obtuvieran acceso completo a los sistemas. Este problema afecta a: Sistema Operativo Arista Metamako MOS-0.13 y versiones posteriores en MOS-0.1x train MOS-0.26.6 y versiones anteriores en MOS-0.2x train MOS-0.31.1 y versiones anteriores en MOS-0.3x train

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-03-16 CVE Reserved
  • 2021-09-09 CVE Published
  • 2023-04-02 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-255: Credentials Management Errors
  • CWE-522: Insufficiently Protected Credentials
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Arista
Search vendor "Arista"
Metamako Operating System
Search vendor "Arista" for product "Metamako Operating System"
>= 0.10.0 <= 0.13.0
Search vendor "Arista" for product "Metamako Operating System" and version " >= 0.10.0 <= 0.13.0"
-
Affected
in Arista
Search vendor "Arista"
7130
Search vendor "Arista" for product "7130"
--
Safe
Arista
Search vendor "Arista"
Metamako Operating System
Search vendor "Arista" for product "Metamako Operating System"
>= 0.26.0 < 0.26.7
Search vendor "Arista" for product "Metamako Operating System" and version " >= 0.26.0 < 0.26.7"
-
Affected
in Arista
Search vendor "Arista"
7130
Search vendor "Arista" for product "7130"
--
Safe
Arista
Search vendor "Arista"
Metamako Operating System
Search vendor "Arista" for product "Metamako Operating System"
>= 0.31.0 < 0.32.0
Search vendor "Arista" for product "Metamako Operating System" and version " >= 0.31.0 < 0.32.0"
-
Affected
in Arista
Search vendor "Arista"
7130
Search vendor "Arista" for product "7130"
--
Safe