Description
On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader actions on managed EOS devices than intended. This advisory impacts the Arista CloudVision Portal products when run on-premise. It does not impact CloudVision as-a-Service.
References (1)
Core 1
Core References
Scores
CVSS v3
10.0
EPSS
0.0064
EPSS Percentile
45.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-287
Status
published
Products (19)
Arista Networks/CloudVision Portal
2017.2
Arista Networks/CloudVision Portal
2018.1
Arista Networks/CloudVision Portal
2018.2
Arista Networks/CloudVision Portal
2019.1
Arista Networks/CloudVision Portal
2020.1
Arista Networks/CloudVision Portal
2020.2
Arista Networks/CloudVision Portal
2020.3
Arista Networks/CloudVision Portal
2021.1
Arista Networks/CloudVision Portal
2021.2
Arista Networks/CloudVision Portal
2021.3
... and 9 more
Published
May 08, 2025
Tracked Since
Feb 18, 2026