Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-29071

Опубликовано: 05 авг. 2022
Источник: nvd
CVSS3: 4
CVSS3: 5.5
EPSS Низкий

Описание

This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certain set of conditions, user passwords can be leaked in the Audit and System logs. The impact of this vulnerability is that the CVP user login passwords might be leaked to other authenticated users.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:arista:cloudvision_portal:*:*:*:*:*:*:*:*
Версия от 2020.2.0 (включая) до 2022.1.0 (включая)

EPSS

Процентиль: 15%
0.00049
Низкий

4 Medium

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-200
CWE-532

Связанные уязвимости

CVSS3: 5.5
github
больше 3 лет назад

This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certain set of conditions, user passwords can be leaked in the Audit and System logs. The impact of this vulnerability is that the CVP user login passwords might be leaked to other authenticated users.

EPSS

Процентиль: 15%
0.00049
Низкий

4 Medium

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-200
CWE-532