CVE-2016-9012
high
CVSS v3
8.8
CVSS v2
6.5
VIR risk
8.8
Description
CloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuration mechanisms via the management plane, related to a request to /web/system/console/bundle.
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — https://www.arista.com/en/support/advisories-notices/security-advisories/2116-security-advisory-27
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| arista | cloudvision_portal | {"endIncluding":"2016.1.2.0"} | |
References
CWEs
CWE-264
Verify integrity in audit chain (admin only). AS-IS.