Arista

Cloudvision Portal

12 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 08.05.2025 19:15:57
  • Zuletzt bearbeitet 12.05.2025 17:32:52

On affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in packets being sent over the secure Vxlan tunnels in the clear.

  • EPSS 0.05%
  • Veröffentlicht 08.05.2025 18:47:52
  • Zuletzt bearbeitet 12.05.2025 17:32:52

On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader actions on managed EOS devices than intended. This advisory impacts the Arista CloudVision Portal products when run o...

  • EPSS 0.04%
  • Veröffentlicht 08.05.2025 18:37:13
  • Zuletzt bearbeitet 12.05.2025 17:32:52

On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain admin privileges on the CloudVision system, with more permissions than necessary, which can be used to query or manipulate system ...

  • EPSS 0.12%
  • Veröffentlicht 13.06.2023 21:15:09
  • Zuletzt bearbeitet 06.01.2025 16:15:25

On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor with network access to CloudVision to get broader access to telemetry and configuration data within t...

  • EPSS 0.05%
  • Veröffentlicht 05.08.2022 17:15:08
  • Zuletzt bearbeitet 21.11.2024 06:58:26

This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certain set of conditions, user passwords can be leaked in the Audit and System logs. The impact of this vu...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 22.09.2020 15:15:14
  • Zuletzt bearbeitet 21.11.2024 05:14:36

A vulnerability in Arista’s CloudVision Portal (CVP) prior to 2020.2 allows users with “read-only” or greater access rights to the Configlet Management module to download files not intended for access, located on the CVP server, by accessing a specif...

  • EPSS 0.86%
  • Veröffentlicht 06.06.2020 19:15:09
  • Zuletzt bearbeitet 21.11.2024 05:02:04

In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel and journald are used.

  • EPSS 0.04%
  • Veröffentlicht 19.12.2019 19:15:14
  • Zuletzt bearbeitet 21.11.2024 04:32:46

In CloudVision Portal all releases in the 2018.1 and 2018.2 Code train allows users with read-only permissions to bypass permissions for restricted functionality via CVP API calls through the Configlet Builder modules. This vulnerability can potentia...

  • EPSS 0.11%
  • Veröffentlicht 19.12.2019 17:15:12
  • Zuletzt bearbeitet 21.11.2024 04:33:22

In CloudVision Portal (CVP) for all releases in the 2018.2 Train, under certain conditions, the application logs user passwords in plain text for certain API calls, potentially leading to user password exposure. This only affects CVP environments whe...

Exploit
  • EPSS 2.34%
  • Veröffentlicht 24.10.2019 22:15:10
  • Zuletzt bearbeitet 21.11.2024 04:32:36

Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.