CVE-2024-8100 Details
Description
On affected versions of the Arista CloudVision Portal (CVP on-prem), the time-bound device onboarding token can be used to gain admin privileges on CloudVision.
A vulnerability exists in Arista CloudVision Portal (CVP on-prem) versions 2024.3.0, 2024.2 and below in the 2024.x train, 2023.3.1 and below in the 2023.3.x train, 2023.2 and below in the 2023.x train, and all releases in the 2022.x, 2021.x, 2020.x, 2019.x, and 2018.x trains. The issue arises because a time-bound device onboarding token can be exploited to gain administrative privileges on CloudVision. This vulnerability was discovered internally, and Arista is not aware of any malicious exploitation in customer networks.
Users are advised to upgrade to version 2024.1.3 or later in the 2024.1.x train, version 2024.2.2 or later in the 2024.2.x train, version 2024.3.1 or later in the 2024.3.x train, or version 2025.1.0 or later in the 2025.1.x train.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 8, 2025CISA-ADP
Assessed May 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.arista.com/en/support/advisories-notices/security-advisory/21316-security-advisory-0116 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Arista CloudVision Portal | 2024.3.0 (semver) ~2024 ~2023.3 ~2023 ~2022 ~2021 ~2020 ~2019 ~2018 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 8, 2025 | New CVE Received | [email protected] |
Volerion