CVE-2022-29071: This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certain set of conditions, user passwords can be leaked in the Audit and System logs. The impact of this vu ...
This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certain set of conditions, user passwords can be leaked in the Audit and System logs. The impact of this vulnerability is that the CVP user login passwords might be leaked to other authenticated users.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-29071?
CVE-2022-29071 is a vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where user passwords can be leaked in the Audit and System logs.
What is the impact of CVE-2022-29071?
The impact of CVE-2022-29071 is that the user login passwords in Arista CloudVision Portal (CVP) can be leaked.
How severe is CVE-2022-29071?
CVE-2022-29071 has a severity rating of 5.5, which is classified as medium.
Which version of Arista CloudVision Portal is affected by CVE-2022-29071?
CVE-2022-29071 affects Arista CloudVision Portal versions between 2020.2.0 and 2022.1.0.
How can I fix CVE-2022-29071?
To fix CVE-2022-29071, it is recommended to update Arista CloudVision Portal to a version beyond 2022.1.0.