Vulnerabilities > Arista > Cloudvision Portal > 2022.1.0

DATE CVE VULNERABILITY TITLE RISK
2023-06-13 CVE-2023-24546 Incorrect Authorization vulnerability in Arista Cloudvision Portal
On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor with network access to CloudVision to get broader access to telemetry and configuration data within the system than intended.
network
low complexity
arista CWE-863
8.1
2022-08-05 CVE-2022-29071 Information Exposure Through Log Files vulnerability in Arista Cloudvision Portal
This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certain set of conditions, user passwords can be leaked in the Audit and System logs.
local
low complexity
arista CWE-532
5.5