Database/Firmware, BMC & network fabric

Arista CloudVision Portal: login flow redirects to an attacker-chosen external site after authentication
Impact
The CVP login flow does not validate the post-authentication redirect target, so a crafted link lands a network operator on an arbitrary external site immediately after they authenticate to CloudVision. The practical use is credential phishing with a convincing CVP-branded hand-off, which matters because CVP credentials control the datacenter fabric. Confidentiality impact is rated low and there is no integrity or availability effect - this is a phishing enabler against fabric operators, not a direct path into CVP.
Who can reach it
Remote and unauthenticated; requires a CVP user to click the crafted URL and complete the login (CVSS UI:P).
What to do
Fixed in the CVP versions listed in Arista security advisory 0187, which also covers CVE-2026-101152; the record here does not name versions. One CVP patch and service restart covers both. No switch or GPU node maintenance is involved, so this can ride along with the next CVP upgrade window rather than forcing one.
References
Related entries
- Arista EOS: VRRPv2 IP-AH authentication bypass lets an attacker claim the virtual router master roleCVE-2026-73444 · Arista EOS VRRPv2 IP Authentication Header (IP-AH) authenticationMedium
- RDMA fabric + remote DRAM bank contention (cross-node covert channel): Bankrupt establishes a 74 Kb/s covert channelNCVD-2020-002-rdma-fabric-remote-dram-bank-con · RDMA fabric + remote DRAM bank contention (cross-node covert channel)Medium
- RDMA fabric + remote DRAM bank contention (cross-node covert channel): Bankrupt establishes a 74 Kb/s covert channelNCVD-2020-004-rdma-fabric-remote-dram-bank-con · RDMA fabric + remote DRAM bank contention (cross-node covert channel)Medium
- AMD Secure Processor TEE - Secure OS stack overrun (AMD-SB-3003): A stack overrun in the ASP Secure OS trustedCVE-2021-46746 · AMD Secure Processor TEE - Secure OS stack overrun (AMD-SB-3003)Medium
- Intel Server OpenBMC firmware (before egs-1.09) - authentication logic: An authenticated low-privilege user escalatesCVE-2023-31189 · Intel Server OpenBMC firmware (before egs-1.09) - authentication logicMedium
- Cisco NX-OS (bootloader / image signature verification): Secure boot on the switch is defeatable: an attackerCVE-2024-20397 · Cisco NX-OS (bootloader / image signature verification)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.