Database/Firmware, BMC & network fabric

Arista CloudVision Portal: crafted SSO URL makes the IdP deliver authentication material to an attacker host
Impact
The SSO login flow does not validate where authentication material is returned, so an attacker who gets a network engineer to click a crafted link can capture the token or assertion the identity provider meant for CloudVision and use it to sign in as that operator. CloudVision is the configuration and telemetry authority for the datacenter fabric, so a captured operator session can reconfigure the switching that carries tenant and storage traffic. No prior access to CVP is needed - only a user willing to click.
Who can reach it
Remote and unauthenticated, but requires a CVP user to click the crafted URL (CVSS UI:P, AC:H). The attacker needs no account on CVP and no position on the management VLAN.
What to do
Upgrade CVP to a version listed in Arista security advisory 0187; the record does not name fixed versions, so take them from the advisory. The work is a CVP patch and service restart on the management appliance, not a fabric or node event. Phishing-resistant mitigation in the meantime is limited to user awareness and IdP-side restrictions on redirect targets.
References
Related entries
- IBM Power Systems Firmware: unauthenticated ASMI web request crashes the service-processor interfaceCVE-2026-16828 · IBM Power Systems Firmware ASMI web interfaceHigh
- Opengear console server: Authentication bypass in the console server allowing remote attackers to modify settingsCVE-2011-3997 · Opengear console serverHigh
- Supermicro IPMI BMC firmware - hardcoded WSMAN credentials (X9 before SMT_X9_315, X8 before SMT X8 312): The BMCCVE-2013-3620 · Supermicro IPMI BMC firmware - hardcoded WSMAN credentials (X9 before SMT_X9_315, X8 before SMT X8 312)High
- IBM Integrated Management Module (IMM/IMM2) IPMI 2.0 RAKP implementation: The vendor-acknowledged instance of the IPMICVE-2013-4037 · IBM Integrated Management Module (IMM/IMM2) IPMI 2.0 RAKP implementationHigh
- IPMI 2.0 RAKP (all vendors): Protocol design flawCVE-2013-4786 · IPMI 2.0 RAKP (all vendors)High
- AMD processors - page table walk traces in the last-level cache: The MMU's page table walks during address translationCVE-2017-5926 · AMD processors - page table walk traces in the last-level cacheHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.