First published: Mon Jan 23 2017(Updated: )
CloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuration mechanisms via the management plane, related to a request to /web/system/console/bundle.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Arista CloudVision Portal | <=2016.1.2.0 | |
<=2016.1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9012 has been classified as a medium severity vulnerability.
To fix CVE-2016-9012, upgrade to CloudVision Portal version 2016.1.2.1 or later.
CVE-2016-9012 exploits a vulnerability that allows remote authenticated users to access internal configuration mechanisms.
CloudVision Portal versions prior to 2016.1.2.1 are affected by CVE-2016-9012.
Yes, CVE-2016-9012 can be exploited by remote authenticated users.