Executive brief
Arista CloudVision Portal, a management platform for network automation and visibility, contains a security flaw that allows logged-in users to access sensitive internal configuration settings. An attacker with basic user credentials could exploit this to gain unauthorized control over the system's management plane. This could lead to full system compromise, data theft, or disruption of network operations.
Technical details
A privilege escalation or improper access control vulnerability exists in Arista CloudVision Portal (CVP) versions prior to 2016.1.2.1. The flaw is located within the management plane and is specifically related to how the system handles requests to the '/web/system/console/bundle' endpoint. A remote attacker with valid low-privileged credentials can send a crafted request to this endpoint to bypass intended access restrictions. Successful exploitation allows the attacker to interact with internal configuration mechanisms, potentially leading to a complete compromise of the CVP instance. The issue is addressed in version 2016.1.2.1 and later.
Affected products
- Arista CloudVision Portal (CVP) Before 2016.1.2.1
Timeline
- 2016-11-30: advisory: SecurityFocus BID 94635 published
- 2017-01-23: disclosed: NVD publication date
- 2016-12-01: patched: Approximate patch availability based on advisory timing