PT-2025-20408 · Arista · Arista Cloudvision

Published

2025-05-08

·

Updated

2025-05-10

·

CVE-2025-0505

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Arista CloudVision (affected versions not specified)
Description The issue allows an attacker to gain admin privileges on the CloudVision system using Zero Touch Provisioning, with more permissions than necessary. This can be used to query or manipulate system state for devices under management. It is noted that CloudVision as-a-Service is not affected.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2025-0505

Affected Products

Arista Cloudvision