Database/Firmware, BMC & network fabric

Arista CloudVision Portal: authenticated path traversal in image repositories reads and writes arbitrary platform files
Impact
CloudVision Portal is the management plane for the Arista leaf/spine fabric a GPU cluster rides on, so writing arbitrary files on the CVP filesystem puts an attacker in a position to tamper with the images and extensions pushed to switches and to read secrets CVP holds for the whole fleet. The upload paths are not confined to their intended directory, so a crafted request or crafted upload reaches the rest of the platform filesystem. Arista split this across two ids for the two affected repositories - CVE-2026-101154 (Network Provisioning image repository) and CVE-2026-101155 (Software Management Studio software repository) - with the same score and the same advisory. The attacker must already hold high privileges in CVP, which narrows this to insider or stolen-credential use, but CVP credentials are exactly what a fabric compromise needs.
Who can reach it
Remote over the network to the CVP web interface, authenticated, and requires an account holding specific high privileges (CVSS PR:H). In most deployments that means reachability from the management VLAN plus a privileged CVP role.
What to do
Apply the CVP release or hotfix named in Arista security advisory 0189; the advisory is the only source for fixed versions, and the record given here does not state them. Remediation is a CVP upgrade or patch and service restart on the management appliance or cluster - no switch reload and no GPU node drain. Until then, restrict network reach to CVP and audit which accounts hold the privileged roles that gate these endpoints.
Also covers 1 CVE
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- Eaton Tripp Lite series PADM firmware (rack PDU / ATS management): Unauthenticated authentication bypass givesCVE-2026-22620 · Eaton Tripp Lite series PADM firmware (rack PDU / ATS management)High
- Arista EOS: crafted gNSI Credentialz request can grant an account privileges beyond what was configuredCVE-2026-73454 · Arista EOS gNSI Credentialz serviceHigh
- InfiniBand / RoCEv2 transport - RNIC connection state (QP number, PSN) on Mellanox ConnectX-class and compatible RNICsNCVD-2021-003-infiniband-rocev2-transport-rnic · InfiniBand / RoCEv2 transport - RNIC connection state (QP number, PSN) on Mellanox ConnectX-class and compatible RNICsHigh
- InfiniBand / RoCEv2 transport - RNIC connection state (QP number, PSN) on Mellanox ConnectX-class and compatible RNICsNCVD-2021-009-infiniband-rocev2-transport-rnic · InfiniBand / RoCEv2 transport - RNIC connection state (QP number, PSN) on Mellanox ConnectX-class and compatible RNICsHigh
- NVMe-over-Fabrics protocol over RDMA - SPDK NVMe-oF target and Linux kernel nvmet: NeVerMore implemented seven attacksNCVD-2022-002-nvme-over-fabrics-protocol-over · NVMe-over-Fabrics protocol over RDMA - SPDK NVMe-oF target and Linux kernel nvmetHigh
- Alias Checking Trusted Module (ACTM) firmware for Intel Xeon processors, including Xeon 6: Improper access controlCVE-2026-20898 · Alias Checking Trusted Module (ACTM) firmware for Intel Xeon processors, including Xeon 6High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.