First published: Tue Sep 22 2020(Updated: )
A vulnerability in Arista’s CloudVision Portal (CVP) prior to 2020.2 allows users with “read-only” or greater access rights to the Configlet Management module to download files not intended for access, located on the CVP server, by accessing a specific API.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Arista CloudVision Portal | <2020.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-24333 is a vulnerability in Arista's CloudVision Portal (CVP) that allows unauthorized file downloads.
The severity of CVE-2020-24333 is medium, with a score of 6.5.
CVE-2020-24333 allows users with "read-only" or greater access rights to the Configlet Management module to download unauthorized files from the CVP server via a specific API.
If your Arista CloudVision Portal version is prior to 2020.2.0, then it is affected by CVE-2020-24333.
To fix CVE-2020-24333, upgrade your Arista CloudVision Portal to version 2020.2.0 or later.