CVE-2024-11186: On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader actions on managed EOS devices than intended. This advisory impacts the Arista CloudVision Portal products when run on-prem
On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader actions on managed EOS devices than intended. This advisory impacts the Arista CloudVision Portal products when run on-premise. It does not impact CloudVision as-a-Service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11186?
CVE-2024-11186 has been rated as a critical severity vulnerability due to improper access controls allowing escalation of privileges.
How do I fix CVE-2024-11186?
To fix CVE-2024-11186, ensure that you apply the latest security patch provided by Arista for the CloudVision Portal.
What systems are affected by CVE-2024-11186?
CVE-2024-11186 affects on-premise installations of the Arista CloudVision Portal.
Who can exploit CVE-2024-11186?
CVE-2024-11186 can be exploited by a malicious authenticated user to gain unauthorized access to managed EOS devices.
What are the risks associated with CVE-2024-11186?
The risks associated with CVE-2024-11186 include unauthorized actions on managed EOS devices, potentially leading to network compromise.