Cloudvision portal
This hub aggregates every CVE we track for Cloudvision portal, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
13
CVEs tracked
3
Critical
6
High
1
In CISA KEV
Severity distribution
HIGH6MEDIUM4CRITICAL3
Monthly trend
0
0
0
0
0
0
0
0
0
3
0
0
0
0
0
0
0
0
0
0
1
0
0
0
2024-082026-07
Latest CVEs
The 13 most recently published vulnerabilities affecting Cloudvision portal.
- CVE-2026-31431crypto: algif_aead - Revert to operating out-of-placeKEV7.8
- CVE-2024-12378On affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in packets being sent over the secure Vxlan tunnels in the clear.9.1
- CVE-2024-11186On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader actions on managed EOS devices than intended. This advisory impacts the Arista CloudVision Portal products when run on-prem10.0
- CVE-2025-0505On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain admin privileges on the CloudVision system, with more permissions than necessary, which can be used to query or manipulate system state10.0
- CVE-2023-24546On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor with network access to CloudVision to get broade...8.1
- CVE-2022-29071This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certain set of conditions, user passwords can be leaked in the Audit and System logs. The impact of this vu ...4.0
- CVE-2020-24333A vulnerability in Arista’s CloudVision Portal (CVP) prior to 2020.2 allows users with “read-only” or greater access rights to the Configlet Management module to download files not intended f...6.5
- CVE-2020-13881In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel and journald are used.7.5
- CVE-2019-18181In CloudVision Portal all releases in the 2018.1 and 2018.2 Code train allows users with read-only permissions to bypass permissions for restricted functionality via CVP API calls through the Confi...7.8
- CVE-2019-18615In CloudVision Portal (CVP) for all releases in the 2018.2 Train, under certain conditions, the application logs user passwords in plain text for certain API calls, potentially leading to user pass...4.9
- CVE-2019-17596Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a clien...7.5
- CVE-2018-12357Arista CloudVision Portal through 2018.1.1 has Incorrect Permissions.6.5
- CVE-2016-9012CloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuration mechanisms via the management plane, related to a request to /web/system/co...8.8
Product normalization is registry-driven with AI assist and human review. How it works