Database/Firmware, BMC & network fabric

Arista CloudVision Portal: unvalidated Fileserver upload stores XSS that hijacks admin sessions
Impact
CloudVision Portal is the management plane for the Arista fabric that carries east-west traffic between GPU nodes and the storage network. An authenticated user who only holds file-upload rights can plant stored script that runs in the browser of any other CloudVision user who views it, including an administrator. Arista scores the scope change as high in both confidentiality and integrity: taking over an admin session means control over switch configuration and change deployment for the whole fabric, so a low-privilege operator account becomes a path to re-provisioning or disrupting tenant-crossing network paths. There is no GPU-node compromise here, but fabric config control is enough to isolate, mirror or blackhole traffic for an entire cluster.
Who can reach it
An authenticated CloudVision user with file upload privileges, reaching the portal over the management network; a second CloudVision user must then view the stored content (the CVSS vector requires passive user interaction).
What to do
Upgrade CloudVision Portal to a fixed release per Arista security advisory 0185; CVP upgrades restart the portal cluster services, so schedule a management-plane maintenance window - the switches keep forwarding, but streaming telemetry and change deployment pause. Until then, restrict file-upload privileges to accounts that need them and treat the portal as sensitive to session hijack. The advisory, not this entry, is the source for exact fixed versions.
References
Related entries
- Phala dcap-qvl - the Rust/npm/Python DCAP quote verification library used to verify Intel SGX and TDX attestationCVE-2026-22696 · Phala dcap-qvl - the Rust/npm/Python DCAP quote verification library used to verify Intel SGX and TDX attestation…Critical
- Voltronic Power SNMP Web Pro: unauthenticated firmware upload yields root on the UPS management cardCVE-2026-44402 · Voltronic Power SNMP Web Pro 1.1 (upload.cgi firmware update endpoint)Critical
- fakefish: KubeVirt backend ignores Redfish credentials, exposing VM power and virtual mediaCVE-2026-71566 · fakefish (Redfish BMC shim, KubeVirt backend)Critical
- Linux kernel (drivers/infiniband/hw/bnxt_re): A user context could request the write-combine doorbell page repeatedlyCVE-2026-72495 · Linux kernel (drivers/infiniband/hw/bnxt_re)Critical
- Phison PS3111-S11 SSD firmware: signature check trusts a modulus carried in the image, so any firmware verifiesCVE-2026-82876 · Phison PS3111-S11 SSD controller firmware (signature verification root of trust)Critical
- Phison PS3111-S11 SSD firmware: vendor unique commands allow persistent implants in controller flashCVE-2026-84696 · Phison PS3111-S11 SSD controller firmware (vendor unique commands over ATA)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.