CVE-2023-24546: High severity arista cloudvision vulnerability
On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor with network access to CloudVision to get broader access to telemetry and configuration data within the system than intended. This advisory impacts the Arista CloudVision Portal product when run on-premise. It does not impact CloudVision as-a-Service.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-24546?
CVE-2023-24546 is a vulnerability that allows a malicious actor with network access to CloudVision to gain broader access to telemetry and configuration data within the system than intended.
How does CVE-2023-24546 impact the CloudVision Portal?
CVE-2023-24546 impacts the CloudVision Portal by allowing improper access controls on the connection from devices to CloudVision.
What is the severity of CVE-2023-24546?
CVE-2023-24546 has a severity rating of 8.1 (high).
Which versions of the CloudVision Portal are affected by CVE-2023-24546?
Affected versions of the CloudVision Portal include 2021.1, 2021.3, 2022.1.0, 2022.1.1, 2022.2.0, 2022.2.1, and 2022.3.0.
How can I fix CVE-2023-24546?
To fix CVE-2023-24546, it is recommended to upgrade to a version of the CloudVision Portal that is not affected by this vulnerability.