CVE-2018-12357
https://notcve.org/view.php?id=CVE-2018-12357
Arista CloudVision Portal through 2018.1.1 has Incorrect Permissions. Arista CloudVision Portal versiones hasta 2018.1.1, presenta Permisos Incorrectos. • https://www.arista.com/en/support/advisories-notices https://www.arista.com/en/support/advisories-notices/security-advisories/5432-security-advisory-35 • CWE-732: Incorrect Permission Assignment for Critical Resource •
CVE-2016-9012
https://notcve.org/view.php?id=CVE-2016-9012
CloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuration mechanisms via the management plane, related to a request to /web/system/console/bundle. CloudVision Portal (CVP) en versiones anteriores a 2016.1.2.1 permite a usuarios remotos autenticados obtener acceso a los mecanismos de configuración internos a través del plano de gestión, relacionados con una petición a /web/system/console/bundle. • http://www.securityfocus.com/bid/94635 https://www.arista.com/en/support/advisories-notices/security-advisories/2116-security-advisory-27 • CWE-264: Permissions, Privileges, and Access Controls •