GPU VulnDB

Database/Firmware, BMC & network fabric

Arista CloudVision Portal: crafted SSO URL makes the IdP deliver authentication material to an attacker host

CVSS 7.6CVE-2026-101152Firmware, BMC & network fabriccurated

Impact

The SSO login flow does not validate where authentication material is returned, so an attacker who gets a network engineer to click a crafted link can capture the token or assertion the identity provider meant for CloudVision and use it to sign in as that operator. CloudVision is the configuration and telemetry authority for the datacenter fabric, so a captured operator session can reconfigure the switching that carries tenant and storage traffic. No prior access to CVP is needed - only a user willing to click.

Who can reach it

Remote and unauthenticated, but requires a CVP user to click the crafted URL (CVSS UI:P, AC:H). The attacker needs no account on CVP and no position on the management VLAN.

What to do

Upgrade CVP to a version listed in Arista security advisory 0187; the record does not name fixed versions, so take them from the advisory. The work is a CVP patch and service restart on the management appliance, not a fabric or node event. Phishing-resistant mitigation in the meantime is limited to user awareness and IdP-side restrictions on redirect targets.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.