← Vulnerability feed

Vulnerability record · CVE-2023-24546 · published 13 June 2023

CVE-2023-24546: Arista cloudvision portal improper access control vulnerability

Arista · Cloudvision Portal

On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor with network access to CloudVision to get broader access to telemetry and configuration data within the system than intended. This advisory impacts the Arista CloudVision Portal product when run on-premise. It does not impact CloudVision as-a-Service.

8.1 CVSS 3.1 High EPSS 0.47% · top 61.5% CWE-284 · Improper access controlCWE-863 · Incorrect authorization
8.1CVSS 3.1 base score
0.47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor with network access to CloudVision to get broader access to telemetry and configuration data within the system than intended. This advisory impacts the Arista CloudVision Portal product when run on-premise. It does not impact CloudVision as-a-Service.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-24546 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2026-31431Linux kernel algif_aead in-place crypto operation flawThe Linux kernel's algif_aead AF_ALG AEAD interface operated in-place on buffers that come from different mappings, a flaw the fix resolves by revert…KEVEPSS 3.4%analysed8.8CVE-2016-9012Arista cloudvision portal permissions and access controls vulnerabilityCloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuration mechanisms via the manageme…EPSS 1.5%7.8CVE-2019-18181Arista cloudvision portal vulnerabilityIn CloudVision Portal all releases in the 2018.1 and 2018.2 Code train allows users with read-only permissions to bypass permissions for restricted f…EPSS 0.34%7.5CVE-2020-13881Pam tacplus project pam tacplus sensitive information in log file vulnerabilityIn support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel and journald are used.EPSS 1.7%7.5CVE-2019-17596Golang go interpretation conflict vulnerabilityGo before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are severa…EPSS 4.7%6.5CVE-2020-24333Arista cloudvision portal vulnerabilityA vulnerability in Arista’s CloudVision Portal (CVP) prior to 2020.2 allows users with “read-only” or greater access rights to the Configlet Manageme…EPSS 0.84%6.5CVE-2018-12357Arista cloudvision portal incorrect permission assignment vulnerabilityArista CloudVision Portal through 2018.1.1 has Incorrect Permissions.EPSS 0.77%5.5CVE-2022-29071Arista cloudvision portal information exposure vulnerabilityThis advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certai…EPSS 0.20%

Source: NIST National Vulnerability Database (record CVE-2023-24546), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.