← Vulnerability feed

Vulnerability record · CVE-2016-9012 · published 23 January 2017

CVE-2016-9012: Arista cloudvision portal permissions and access controls vulnerability

Arista · Cloudvision Portal

CloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuration mechanisms via the management plane, related to a request to /web/system/console/bundle.

8.8 CVSS 3.0 High EPSS 1.5% · top 26.6% CWE-264 · Permissions and access controls
8.8CVSS 3.0 base score, v2 6.5
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

CloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuration mechanisms via the management plane, related to a request to /web/system/console/bundle.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-9012 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2026-31431Linux kernel algif_aead in-place crypto operation flawThe Linux kernel's algif_aead AF_ALG AEAD interface operated in-place on buffers that come from different mappings, a flaw the fix resolves by revert…KEVEPSS 3.4%analysed8.1CVE-2023-24546Arista cloudvision portal improper access control vulnerabilityOn affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor …EPSS 0.47%7.8CVE-2019-18181Arista cloudvision portal vulnerabilityIn CloudVision Portal all releases in the 2018.1 and 2018.2 Code train allows users with read-only permissions to bypass permissions for restricted f…EPSS 0.34%7.5CVE-2020-13881Pam tacplus project pam tacplus sensitive information in log file vulnerabilityIn support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel and journald are used.EPSS 1.7%7.5CVE-2019-17596Golang go interpretation conflict vulnerabilityGo before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are severa…EPSS 4.7%6.5CVE-2020-24333Arista cloudvision portal vulnerabilityA vulnerability in Arista’s CloudVision Portal (CVP) prior to 2020.2 allows users with “read-only” or greater access rights to the Configlet Manageme…EPSS 0.84%6.5CVE-2018-12357Arista cloudvision portal incorrect permission assignment vulnerabilityArista CloudVision Portal through 2018.1.1 has Incorrect Permissions.EPSS 0.77%5.5CVE-2022-29071Arista cloudvision portal information exposure vulnerabilityThis advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certai…EPSS 0.20%

Source: NIST National Vulnerability Database (record CVE-2016-9012), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.