Database/Firmware, BMC & network fabric

Arista CloudVision Portal: OIDC configuration accepts arbitrary destinations, letting an admin aim CVP requests outward
Impact
CVP does not validate the endpoints given in its OIDC single sign-on provider configuration or its OIDC bearer token configuration, so an administrator can make the CVP server issue requests to destinations of their choosing. On a management appliance that sits inside the management VLAN, that turns CVP into a request relay toward hosts an outside attacker cannot reach directly, and it can send authentication traffic somewhere the operator does not control. Arista assigned two ids for the two configuration paths - CVE-2026-101149 (SSO provider config) and CVE-2026-101150 (bearer token config) - under one advisory with the same score and the same fix. Impact is bounded by the fact that only an already highly privileged CVP user can change this configuration; the CVSS scores it as crossing a trust boundary (SC:L) rather than as data loss.
Who can reach it
Remote over the network to the CVP configuration interface, authenticated as a user with specific high privileges (CVSS PR:H). No user interaction.
What to do
Upgrade CVP per Arista security advisory 0186 - the advisory holds the fixed versions, which this record does not state. The action is a CVP patch and service restart on the management appliance; nothing to do on switches or GPU nodes. Interim control is limiting who holds the CVP roles that can edit SSO configuration and watching egress from the CVP host.
Also covers 1 CVE
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- NVIDIA UFM Enterprise: hard-coded key in session management allows information disclosure and privilege escalationCVE-2026-24166 · NVIDIA UFM Enterprise (session management, hard-coded cryptographic key)Medium
- IBM PowerVM PKS and virtual TPM: persistent key seeds produce a reduced-strength AES keyCVE-2026-4936 · IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM, FW950 / FW1060 / FW1110Medium
- OpenIPMI before 2.0.36: Where this bites an operator is in test and CI infrastructure rather than production nodesCVE-2024-42934 · OpenIPMI before 2.0.36Medium
- Dell SmartFabric OS10: command injection lets a high-privileged remote user run arbitrary OS commandsCVE-2026-35160 · Dell SmartFabric OS10 (switch NOS command handling)Medium
- Eaton UPS 9PX 8000 SP web interface: The device's own web page contains the user password in cleartext in the pageCVE-2018-9279 · Eaton UPS 9PX 8000 SP web interfaceMedium
- NVIDIA DGX BMC (AMI firmware): An administrative BMC user can pull the hash of the BMC/IPMI user passwordCVE-2020-11484 · NVIDIA DGX BMC (AMI firmware)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.