PT-2020-15685 · Arista · Arista Cloudvision Portal

Published

2020-09-22

·

Updated

2021-07-21

·

CVE-2020-24333

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Arista CloudVision Portal versions prior to 2020.2
Description A vulnerability allows users with "read-only" or greater access rights to the Configlet Management module to download unauthorized files from the server by accessing a specific API.
Recommendations For versions prior to 2020.2, update to version 2020.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the Configlet Management module to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-24333

Affected Products

Arista Cloudvision Portal