Database/Control plane, storage & DevOps

Arista CloudVision Portal (Configlet Builder API): A read-only CloudVision user escapes their permissions through
CVSS 7.8CVE-2019-18181Control plane, storage & DevOpscurated
Impact
A read-only CloudVision user escapes their permissions through Configlet Builder API calls and can execute restricted functionality. Read-only accounts are the ones handed out most freely — dashboards, auditors, tenant liaisons — so this is a large-blast-radius privilege escalation on the fabric controller.
Who can reach it
Any authenticated read-only CVP user with API access.
What to do
CloudVision Portal upgrade. Controller-side, no switch impact. Review Configlet Builder execution history for anything run by a read-only principal.
References
Related entries
- MUNGE (SUSE/openSUSE packaging): The munge package's install scripts follow symlinks, so a local attacker who controlsCVE-2019-3691 · MUNGE (SUSE/openSUSE packaging)High
- IBM Spectrum Scale administrative command path: A local unprivileged user becomes root on a Storage Scale node byCVE-2019-4558 · IBM Spectrum Scale administrative command pathHigh
- targetcli-fb 2.1.50/2.1.51 and rtslib-fb through 2.1.72 (configuration tooling for the Linux LIO iSCSI/NVMe-oF target)CVE-2020-10699 · targetcli-fb 2.1.50/2.1.51 and rtslib-fb through 2.1.72 (configuration tooling for the Linux LIO iSCSI/NVMe-oF target)High
- IBM Platform LSF / Spectrum LSF Suite (debug configuration file permissions): With specific debug settings enabled, LSFCVE-2020-4278 · IBM Platform LSF / Spectrum LSF Suite (debug configuration file permissions)High
- IBM Spectrum LSF / LSF Suite (authentication, hard-coded credentials): A user who is merely allowed to submit LSF jobsCVE-2020-4983 · IBM Spectrum LSF / LSF Suite (authentication, hard-coded credentials)High
- AMD System Management Unit (SMU) mailbox interface: A malicious user can manipulate SMU mailbox entries and reachCVE-2021-26331 · AMD System Management Unit (SMU) mailbox interfaceHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.