CVE-2019-18181: High severity arista cloudvision vulnerability
In CloudVision Portal all releases in the 2018.1 and 2018.2 Code train allows users with read-only permissions to bypass permissions for restricted functionality via CVP API calls through the Configlet Builder modules. This vulnerability can potentially enable authenticated users with read-only access to take actions that are otherwise restricted in the GUI.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this security vulnerability?
The vulnerability ID is CVE-2019-18181.
What is the severity of CVE-2019-18181?
The severity of CVE-2019-18181 is high with a CVSS score of 7.8.
What is the affected software for CVE-2019-18181?
The affected software is Arista CloudVision Portal, versions 2018.1.0 to 2018.1.4 and versions 2018.2.0 to 2018.2.3.
How does CVE-2019-18181 impact the system?
CVE-2019-18181 allows users with read-only permissions to bypass restrictions and access restricted functionality via CVP API calls through the Configlet Builder modules.
Is there a fix for CVE-2019-18181?
Yes, it is recommended to update the Arista CloudVision Portal to a version outside the affected range to mitigate this vulnerability.