Description
On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor with network access to CloudVision to get broader access to telemetry and configuration data within the system than intended. This advisory impacts the Arista CloudVision Portal product when run on-premise. It does not impact CloudVision as-a-Service.
References (1)
Core 1
Core References
Scores
CVSS v3
8.1
EPSS
0.0047
EPSS Percentile
37.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-284
CWE-863
Status
published
Products (6)
arista/cloudvision_portal
2022.1.0
arista/cloudvision_portal
2022.1.1
arista/cloudvision_portal
2022.2.0
arista/cloudvision_portal
2022.2.1
arista/cloudvision_portal
2022.3.0
arista/cloudvision_portal
2021.1 - 2021.3
Published
Jun 13, 2023
Tracked Since
Feb 18, 2026