CVE-2026-101152: falha de alta gravidade em Arista Networks CloudVision Portal
Security Advisory 0187
Publicada em
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 7.6epss 0.4%
probabilidade de exploração
0.4%top 70% das CVEs
exploração observada
nãonenhuma fonte reporta
Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, causes the identity provider (IdP) to deliver authentication material to an attacker-controlled URL instead of to CloudVision.
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Produtos afetados
Arista Networks · CloudVision PortalCVEs relacionadas — Arista Networks CloudVision Portal
No mesmo produto, das mais perigosas para as menos.
CVE-2024-11186CRITICALOn affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader actions on managed EOS devices than intended. This advisory impacts the Arista CloudVision Portal products when run on-premEPSS 0.8%CVE-2025-0505CRITICALOn Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain admin privileges on the CloudVision system, with more permissions than necessary, which can be used to query or manipulate system stateEPSS 0.7%CVE-2026-101155HIGHSecurity Advisory 0189EPSS 0.6%CVE-2026-101154HIGHSecurity Advisory 0189EPSS 0.6%CVE-2024-12378CRITICALOn affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in packets being sent over the secure Vxlan tunnels in the clear.EPSS 0.5%CVE-2026-101153HIGHSecurity Advisory 0188EPSS 0.3%