Home
HIGH: 8.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:NDefault status
unaffected
2024.3.0 (custom)
affected
2024.0 (custom)
affected
2023.3.0 (custom)
affected
2023.0 (custom)
affected
2022 (custom)
affected
2021 (custom)
affected
2020 (custom)
affected
2019 (custom)
affected
2018 (custom)
affected
Description
On affected versions of the Arista CloudVision Portal (CVP on-prem), the time-bound device onboarding token can be used to gain admin privileges on CloudVision.
Problem types
CWE-269 Improper Privilege Management
Product status
2024.3.0 (custom)
2024.0 (custom)
2023.3.0 (custom)
2023.0 (custom)
2022 (custom)
2021 (custom)
2020 (custom)
2019 (custom)
2018 (custom)
References
www.arista.com/...rity-advisory/21316-security-advisory-0116