On affected versions of the Arista CloudVision Portal (CVP on-prem), the time-bound device onboarding token can be used to gain admin privileges on CloudVision.
Metrics
Affected Vendors & Products
References
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 08 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 May 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | On affected versions of the Arista CloudVision Portal (CVP on-prem), the time-bound device onboarding token can be used to gain admin privileges on CloudVision. | |
| Title | On affected versions of the Arista CloudVision Portal (CVP on-prem), the time-bound device onboarding token can be used to gain admin privileges on CloudVision. | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Arista
Published: 2025-05-08T18:31:39.114Z
Updated: 2025-05-08T18:57:09.478Z
Reserved: 2024-08-22T18:18:50.804Z
Link: CVE-2024-8100
Updated: 2025-05-08T18:57:02.574Z
Status : Awaiting Analysis
Published: 2025-05-08T19:16:01.183
Modified: 2025-05-12T17:32:52.810
Link: CVE-2024-8100
No data.