Description
On affected versions of the Arista CloudVision Portal (CVP on-prem), the time-bound device onboarding token can be used to gain admin privileges on CloudVision.
References (1)
Core 1
Core References
Scores
CVSS v3
8.7
EPSS
0.0051
EPSS Percentile
39.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-269
Status
published
Products (9)
Arista Networks/CloudVision
2018
Arista Networks/CloudVision
2019
Arista Networks/CloudVision
2020
Arista Networks/CloudVision
2021
Arista Networks/CloudVision
2022
Arista Networks/CloudVision
2023.0 - 2023.2
Arista Networks/CloudVision
2023.3.0 - 2023.3.1
Arista Networks/CloudVision
2024.0 - 2024.2
Arista Networks/CloudVision
2024.3.0
Published
May 08, 2025
Tracked Since
Feb 18, 2026