CVE-2026-101154: falha de alta gravidade em Arista Networks CloudVision Portal
Security Advisory 0189
Publicada em · Atualizada em
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 8.6epss 0.6%
probabilidade de exploração
0.6%top 55% das CVEs
exploração observada
nãonenhuma fonte reporta
An authenticated remote attacker with specific permissions can read or write files on the platform filesystem beyond the intended scope through specially crafted requests and/or crafted file uploads to the Network Provisioning Image Repository.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Produtos afetados
Arista Networks · CloudVision PortalCVEs relacionadas — Arista Networks CloudVision Portal
No mesmo produto, das mais perigosas para as menos.
CVE-2024-11186CRITICALOn affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader actions on managed EOS devices than intended. This advisory impacts the Arista CloudVision Portal products when run on-premEPSS 0.8%CVE-2025-0505CRITICALOn Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain admin privileges on the CloudVision system, with more permissions than necessary, which can be used to query or manipulate system stateEPSS 0.7%CVE-2026-101155HIGHSecurity Advisory 0189EPSS 0.6%CVE-2024-12378CRITICALOn affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in packets being sent over the secure Vxlan tunnels in the clear.EPSS 0.5%CVE-2026-101152HIGHSecurity Advisory 0187EPSS 0.4%CVE-2026-101153HIGHSecurity Advisory 0188EPSS 0.3%