Arista Networks CloudVision Portal是美国Arista Networks公司的一套用于CloudVision平台的、基于Web的用户管理门户。该产品包括网络设备配置、合规性管理、变更管理和网络监控管理等功能。 Arista Networks CloudVision Portal存在安全漏洞,该漏洞源于访问控制不当,可能导致恶意认证用户对管理的EOS设备执行超出预期的操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Arista Networks | CloudVision Portal | 2024.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-0505 | 10.0 CRITICAL | On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Pro |
| CVE-2024-12378 | 9.1 CRITICAL | On affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunn |
| CVE-2024-8100 | 8.7 HIGH | On affected versions of the Arista CloudVision Portal (CVP on-prem), the time-bound device |
| CVE-2024-9448 | 7.5 HIGH | On affected platforms running Arista EOS with Traffic Policies configured the vulnerabilit |
No comments yet