Impact
The vulnerability originates from insufficient validation of OIDC bearer token configuration in Arista Networks CloudVision Portal, allowing a user with high privileges to manipulate settings and direct authenticated requests to arbitrary destinations. This misconfiguration can result in sensitive data being sent to malicious endpoints, potential data exfiltration or further exploitation through the redirected traffic. The underlying weakness aligns with CWE-918, which highlights the risk of unsafe handling of redirect parameters or bearer token misuse.
Affected Systems
Arista Networks CloudVision Portal versions prior to 2026.2.1 in the 2026.2.x train, prior to 2026.1.3 in the 2026.1.x train, and prior to 2025.3.4 in the 2025.3.x train are affected. Only newer releases of these trains mitigate the issue.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity vulnerability, but the EPSS score is unavailable, suggesting uncertain exploitation probability. The vulnerability is not listed in the CISA KEV catalog, implying no current evidence of widespread active exploitation. Attackers would need elevated privileges to OIDC configuration, limiting the attack surface to trusted personnel.
OpenCVE Enrichment