Database/Control plane, storage & DevOps

Arista CloudVision Portal (on-premise): An authenticated CloudVision user can take actions on managed EOS devices well
Impact
An authenticated CloudVision user can take actions on managed EOS devices well beyond what their role should allow. CloudVision is the fabric's configuration and streaming-telemetry brain, so 'broader actions than intended' means pushing configlets to switches you were never granted. In a shared operations model — a neocloud with tenant-facing NOC accounts, or an MSP — this collapses the internal privilege model for the entire fabric.
Who can reach it
Any authenticated CloudVision Portal user on an on-premise deployment.
What to do
Upgrade CloudVision Portal. Application upgrade on the CVP cluster; the switches keep forwarding. Afterwards review the CVP change log for configlet pushes that did not come from an authorized operator — that audit is the real work.
References
Related entries
- ConnectWise ScreenConnect: Auth bypass via alternate pathCVE-2024-1709 · ConnectWise ScreenConnectCritical
- Intel Neural Compressor: An unauthenticated user can reach an input-validation failure in Neural CompressorCVE-2024-22476 · Intel Neural CompressorCritical
- Palo Alto PAN-OS: GlobalProtect arbitrary file creationCVE-2024-3400 · Palo Alto PAN-OSCritical
- GitLab (ruby-saml): Ruby-SAML does not properly verify the SAML Response signatureCVE-2024-45409 · GitLab (ruby-saml)Critical
- Gitea: Stored cross-site scripting in Gitea 1.22.0CVE-2024-6886 · GiteaCritical
- Progress Kemp LoadMaster (including Multi-Tenancy edition): A request handler fails to validate its input beforeCVE-2024-7591 · Progress Kemp LoadMaster (including Multi-Tenancy edition)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.