CVE-2023-24546

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Jun 13, 2023
Updated: Jan 6, 2025
CWE ID 863
CWE ID 284

Summary

CVE-2023-24546 is a vulnerability affecting the Arista CloudVision Portal. The issue lies in improper access controls for device connections to CloudVision, allowing unintended access to telemetry and configuration data. This could potentially enable a malicious actor with network access to CloudVision to gain broader system privileges. This vulnerability only impacts the on-premise version of Arista CloudVision Portal and does not affect CloudVision as-a-Service.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share