CVE-2024-8100: On affected versions of the Arista CloudVision Portal (CVP on-prem), the time-bound device onboarding token can be used to gain admin privileges on CloudVision.
On affected versions of the Arista CloudVision Portal (CVP on-prem), the time-bound device onboarding token can be used to gain admin privileges on CloudVision.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8100?
CVE-2024-8100 has a high severity rating due to its potential to allow unauthorized admin access to the Arista CloudVision Portal.
How do I fix CVE-2024-8100?
To mitigate CVE-2024-8100, update to the latest version of the Arista CloudVision Portal that addresses this vulnerability.
What are the impacts of CVE-2024-8100?
CVE-2024-8100 can allow an attacker to use a compromised onboarding token to gain full administrative privileges on the Arista CloudVision Portal.
Which versions of Arista CloudVision are affected by CVE-2024-8100?
CVE-2024-8100 affects specific versions of the Arista CloudVision Portal, primarily those that utilize the time-bound device onboarding token feature.
Is there a workaround for CVE-2024-8100?
A temporary workaround for CVE-2024-8100 includes revoking affected onboarding tokens until the software can be updated.