GPU VulnDB

Database/Firmware, BMC & network fabric

Arista CloudVision: path traversal lets a high-privilege user read unintended files from the Sensor

CVSS 7.2CVE-2026-101153Firmware, BMC & network fabriccurated

Impact

A path traversal in on-premises CloudVision Portal and CloudVision Sensor lets an already highly privileged authenticated user pull files the Sensor was not meant to expose. On a fabric management appliance that can mean credentials, certificates or device inventory covering the switches in front of the GPU fleet, which is why Arista rates the scope change high. The privilege bar is high and the complexity is high, so this is a privilege-escalation and secrets-exposure problem inside the management plane rather than an entry point from outside it. Treat it as a reason to rotate anything the Sensor holds if you suspect misuse, not as an emergency fabric outage risk.

Who can reach it

Authenticated user with high privileges on CloudVision Portal (on-premises) or the CloudVision Sensor, reachable from the management VLAN. Authentication and elevated rights are both required.

What to do

Upgrade CloudVision Portal / Sensor to a fixed release per Arista security advisory 0188. This is a management-plane service upgrade and restart, not a switch reload; data-plane forwarding is unaffected but telemetry collection pauses during the restart. Keep high-privilege CloudVision accounts to a minimum and audit who holds them. Arista's advisory is the authority on fixed versions.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.