CloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuration mechanisms via the management plane, related to a request to /web/system/console/bundle.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://www.arista.com/en/support/advisories-notices/security-advisories/2116-security-advisory-27 | vendor advisory |
http://www.securityfocus.com/bid/94635 | vdb entry third party advisory |