CVE-2020-24333: Medium severity arista cloudvision vulnerability
A vulnerability in Arista’s CloudVision Portal (CVP) prior to 2020.2 allows users with “read-only” or greater access rights to the Configlet Management module to download files not intended for access, located on the CVP server, by accessing a specific API.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-24333?
CVE-2020-24333 is a vulnerability in Arista's CloudVision Portal (CVP) that allows unauthorized file downloads.
What is the severity of CVE-2020-24333?
The severity of CVE-2020-24333 is medium, with a score of 6.5.
How does CVE-2020-24333 affect Arista CloudVision Portal?
CVE-2020-24333 allows users with "read-only" or greater access rights to the Configlet Management module to download unauthorized files from the CVP server via a specific API.
How can I check if my version of Arista CloudVision Portal is affected by CVE-2020-24333?
If your Arista CloudVision Portal version is prior to 2020.2.0, then it is affected by CVE-2020-24333.
How can I fix CVE-2020-24333 in Arista CloudVision Portal?
To fix CVE-2020-24333, upgrade your Arista CloudVision Portal to version 2020.2.0 or later.