Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hww7-wgc5-5m95

Опубликовано: 13 июн. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor with network access to CloudVision to get broader access to telemetry and configuration data within the system than intended. This advisory impacts the Arista CloudVision Portal product when run on-premise. It does not impact CloudVision as-a-Service.

On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor with network access to CloudVision to get broader access to telemetry and configuration data within the system than intended. This advisory impacts the Arista CloudVision Portal product when run on-premise. It does not impact CloudVision as-a-Service.

EPSS

Процентиль: 32%
0.00121
Низкий

8.1 High

CVSS3

Дефекты

CWE-284
CWE-863

Связанные уязвимости

CVSS3: 8.1
nvd
больше 2 лет назад

On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor with network access to CloudVision to get broader access to telemetry and configuration data within the system than intended. This advisory impacts the Arista CloudVision Portal product when run on-premise. It does not impact CloudVision as-a-Service.

EPSS

Процентиль: 32%
0.00121
Низкий

8.1 High

CVSS3

Дефекты

CWE-284
CWE-863