Back to overview

CVE-2024-11186

CRITICAL
10.0
CVSS 3.1
Description
On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader actions on managed EOS devices than intended. This advisory impacts the Arista CloudVision Portal products when run on-premise. It does not impact CloudVision as-a-Service.

Metadata

CVE ID
CVE-2024-11186
State
PUBLISHED
Assigner
Arista
Reserved
2024-11-13 17:09 UTC
Published
2025-05-08 18:47 UTC
Last updated
2025-05-08 19:01 UTC
Primary CWE
CWE-287
CWE-287 Improper Authentication
Vendor / Product
Arista Networks / CloudVision Portal
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Arista Networks CloudVision Portal 2024.3.0, 2024.2.0 ≤ 2024.2.1, 2024.1.0 ≤ 2024.1.2, 2023.3 …
Weakness (CWE)
CWESourceDescription
CWE-287 cna CWE-287 Improper Authentication
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview