GPU VulnDB

Database/Firmware, BMC & network fabric

Arista CloudVision Portal: authenticated path traversal in image repositories reads and writes arbitrary platform files

CVSS 8.6CVE-2026-101154Firmware, BMC & network fabric+1 more CVEscurated

Impact

CloudVision Portal is the management plane for the Arista leaf/spine fabric a GPU cluster rides on, so writing arbitrary files on the CVP filesystem puts an attacker in a position to tamper with the images and extensions pushed to switches and to read secrets CVP holds for the whole fleet. The upload paths are not confined to their intended directory, so a crafted request or crafted upload reaches the rest of the platform filesystem. Arista split this across two ids for the two affected repositories - CVE-2026-101154 (Network Provisioning image repository) and CVE-2026-101155 (Software Management Studio software repository) - with the same score and the same advisory. The attacker must already hold high privileges in CVP, which narrows this to insider or stolen-credential use, but CVP credentials are exactly what a fabric compromise needs.

Who can reach it

Remote over the network to the CVP web interface, authenticated, and requires an account holding specific high privileges (CVSS PR:H). In most deployments that means reachability from the management VLAN plus a privileged CVP role.

What to do

Apply the CVP release or hotfix named in Arista security advisory 0189; the advisory is the only source for fixed versions, and the record given here does not state them. Remediation is a CVP upgrade or patch and service restart on the management appliance or cluster - no switch reload and no GPU node drain. Until then, restrict network reach to CVP and audit which accounts hold the privileged roles that gate these endpoints.

Also covers 1 CVE

The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.

CVE-2026-101155

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.