GPU VulnDB

Database/Firmware, BMC & network fabric

Arista CloudVision Portal: login flow redirects to an attacker-chosen external site after authentication

CVSS 5.3CVE-2026-101151Firmware, BMC & network fabriccurated

Impact

The CVP login flow does not validate the post-authentication redirect target, so a crafted link lands a network operator on an arbitrary external site immediately after they authenticate to CloudVision. The practical use is credential phishing with a convincing CVP-branded hand-off, which matters because CVP credentials control the datacenter fabric. Confidentiality impact is rated low and there is no integrity or availability effect - this is a phishing enabler against fabric operators, not a direct path into CVP.

Who can reach it

Remote and unauthenticated; requires a CVP user to click the crafted URL and complete the login (CVSS UI:P).

What to do

Fixed in the CVP versions listed in Arista security advisory 0187, which also covers CVE-2026-101152; the record here does not name versions. One CVP patch and service restart covers both. No switch or GPU node maintenance is involved, so this can ride along with the next CVP upgrade window rather than forcing one.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.