Impact
The vulnerability resides in the Single Sign‑On (SSO) login flow of Arista Networks CloudVision Portal. Insufficient validation of URL parameters allows an attacker to craft a malicious link that, when clicked by a legitimate user, causes the identity provider to deliver authentication data to a URL controlled by the attacker. This flaw, which aligns with CWE‑601 (Open Redirect), enables credential theft or session hijacking without requiring any prior authentication with CloudVision.
Affected Systems
Arista Networks CloudVision Portal is affected in all releases prior to 2026.2.1, 2026.1.3, and 2025.3.4. Any deployment of older builds that has not applied these updates is vulnerable.
Risk and Exploitability
The CVSS base score of 7.6 indicates a high severity vulnerability. Because no EPSS value is available, the precise likelihood of exploitation cannot be quantified, and the vulnerability is not enumerated in the CISA KEV catalog. Attackers can exploit this flaw remotely and unauthenticated by simply enticing users to open the malicious URL. Once executed, the attacker can obtain authentication material and potentially gain unauthorized access to the CloudVision environment, compromising both confidentiality and integrity of user sessions.
OpenCVE Enrichment