Impact
The vulnerability is a path traversal flaw that allows an authenticated user with sufficient high privileges to access files that are not intended to be exposed. By manipulating file paths, the attacker can read sensitive data stored in the CloudVision Sensor, potentially leaking configuration or monitoring information.
Affected Systems
This flaw affects Arista Networks CloudVision Portal versions prior to 2026.2.1 (2026.2.x train) and prior to 2026.1.3 (2026.1.x train). It also impacts CloudVision Sensor versions prior to 1.4.3 within the 1.4.x train. The vulnerability exists on both on‑premises deployments of the portal and standalone sensor components.
Risk and Exploitability
The CVSS score of 7.2 classifies the issue as high severity, but the EPSS score is not available, indicating no publicly reported exploit data. The vendor lists the vulnerability under the Common Weakness enumeration CWE‑22. Attack requires authenticated, high‑privilege access to the portal or sensor. Once authenticated, the path traversal can be used to read files outside the intended directory, potentially exposing confidential sensor data. The vulnerability is not currently present in the CISA KEV catalog.
OpenCVE Enrichment