PT-2019-15259 · Aruba · Cloudvision Portal

Published

2019-12-19

·

Updated

2020-08-24

·

CVE-2019-18181

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CloudVision Portal versions 2018.1 through 2018.2
Description The issue allows users with read-only permissions to bypass restrictions for certain functionality through API calls in the Configlet Builder modules. This can enable authenticated users with read-only access to perform actions that are otherwise restricted in the graphical user interface.
Recommendations For CloudVision Portal versions 2018.1 through 2018.2, consider restricting access to the Configlet Builder modules until a fix is available. As a temporary workaround, limit the use of CVP API calls to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-18181

Affected Products

Cloudvision Portal