Impact
Insufficient validation of the request during the CloudVision Portal login flow allows a remote, unauthenticated attacker to craft a URL that, when clicked by a user, redirects the user’s browser to an arbitrary external site after authentication completes. This open‑redirect flaw (CWE‑601) can enable phishing, malware downloads, or credential theft if the target site hosts malicious content.
Affected Systems
The flaw is present in Arista Networks’ CloudVision Portal in all releases prior to 2026.2.1 in the 2026.2.x train, 2026.1.3 in the 2026.1.x train, and 2025.3.4 in the 2025.3.x train.
Risk and Exploitability
The CVSS score of 5.3 denotes a moderate severity. Exploration of the EPSS score indicates it is not publicly available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited current exploitation. Nevertheless, because the attacker only needs to craft a malicious link and relies on a user to click it, the risk is mainly social engineering; patching remains prudent to prevent eventual exploitation.
OpenCVE Enrichment