Arista

Cloudvision Portal

21 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.56%
  • Veröffentlicht 06.10.2026 19:38:23
  • Zuletzt bearbeitet 07.10.2026 13:38:48

An authenticated remote attacker with specific permissions can read or write files on the platform filesystem beyond the intended scope through specially crafted requests and/or crafted file uploads to the Software Management Studio Software Reposito...

  • EPSS 0.56%
  • Veröffentlicht 06.10.2026 19:38:22
  • Zuletzt bearbeitet 07.10.2026 17:16:45

An authenticated remote attacker with specific permissions can read or write files on the platform filesystem beyond the intended scope through specially crafted requests and/or crafted file uploads to the Network Provisioning Image Repository.

  • EPSS 0.33%
  • Veröffentlicht 06.10.2026 19:38:07
  • Zuletzt bearbeitet 07.10.2026 13:38:48

On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vulnerability exists. An authenticated user with sufficient high privileges could exploit this to extract unintended data from the Sensor.

  • EPSS 0.38%
  • Veröffentlicht 06.10.2026 19:37:53
  • Zuletzt bearbeitet 07.10.2026 13:38:48

Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, causes the identity provider (IdP) to deliver authentication material to an attacker-controlled...

  • EPSS 0.31%
  • Veröffentlicht 06.10.2026 19:37:53
  • Zuletzt bearbeitet 07.10.2026 13:38:48

Insufficient validation of request in login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, redirects the user's browser to an arbitrary external site upon completion of the authentication process.

  • EPSS 0.22%
  • Veröffentlicht 06.10.2026 19:37:25
  • Zuletzt bearbeitet 07.10.2026 13:38:48

Insufficient validation of OIDC bearer token configuration could allow a user with specific high privileges to direct requests to arbitrary destinations.

  • EPSS 0.22%
  • Veröffentlicht 06.10.2026 19:37:25
  • Zuletzt bearbeitet 07.10.2026 13:38:48

Insufficient validation of OIDC SSO provider configuration could allow a user with specific high privileges to direct requests to arbitrary destinations.

  • EPSS 0.28%
  • Veröffentlicht 06.10.2026 19:36:51
  • Zuletzt bearbeitet 07.10.2026 13:38:48

A missing input validation vulnerability in the Fileserver upload API allows an authenticated attacker with file upload privileges to execute stored cross-site scripting (XSS). Successful exploitation could enable the attacker to hijack another Cloud...

Warnung Medienbericht Exploit
  • EPSS 99.91%
  • Veröffentlicht 22.04.2026 08:15:10
  • Zuletzt bearbeitet 08.09.2026 15:13:07

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-pl...

  • EPSS 0.5%
  • Veröffentlicht 08.05.2025 19:15:57
  • Zuletzt bearbeitet 15.04.2026 00:35:42

On affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in packets being sent over the secure Vxlan tunnels in the clear.