Vulnerability Description
A vulnerability in Arista’s CloudVision Portal (CVP) prior to 2020.2 allows users with “read-only” or greater access rights to the Configlet Management module to download files not intended for access, located on the CVP server, by accessing a specific API.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Arista | Cloudvision Portal | < 2020.2.0 |
References
- https://www.arista.com/en/support/advisories-noticesVendor Advisory
- https://www.arista.com/en/support/advisories-notices/security-advisories/11706-sExploitMitigationVendor Advisory
- https://www.arista.com/en/support/advisories-noticesVendor Advisory
- https://www.arista.com/en/support/advisories-notices/security-advisories/11706-sExploitMitigationVendor Advisory
FAQ
What is CVE-2020-24333?
CVE-2020-24333 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A vulnerability in Arista’s CloudVision Portal (CVP) prior to 2020.2 allows users with “read-only” or greater access rights to the Configlet Management module to download files not intended for access...
How severe is CVE-2020-24333?
CVE-2020-24333 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-24333?
Check the references section above for vendor advisories and patch information. Affected products include: Arista Cloudvision Portal.