CVE-2025-0505Improper Privilege Management in Networks Cloudvision Portal

Severity
10.0CRITICALNVD
EPSS
0.3%
top 46.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 8

Description

On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain admin privileges on the CloudVision system, with more permissions than necessary, which can be used to query or manipulate system state for devices under management. Note that CloudVision as-a-Service is not affected.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.8

Affected Packages1 packages

CVEListV5arista_networks/cloudvision_portal2024.2.02024.2.1+1

🔴Vulnerability Details

2
GHSA
GHSA-v3m4-v33x-7jhp: On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain admin privileges on the CloudV2025-05-08
CVEList
On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain admin privileges on the CloudVision system, with more permissions than necessary2025-05-08