On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain admin privileges on the CloudVision system, with more permissions than necessary, which can be used to query or manipulate system state for devices under management. Note that CloudVision as-a-Service is not affected.
History

Thu, 08 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 May 2025 18:45:00 +0000

Type Values Removed Values Added
Description On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain admin privileges on the CloudVision system, with more permissions than necessary, which can be used to query or manipulate system state for devices under management. Note that CloudVision as-a-Service is not affected.
Title On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain admin privileges on the CloudVision system, with more permissions than necessary, which can be used to query or manipulate system state
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published: 2025-05-08T18:37:13.981Z

Updated: 2025-05-08T18:56:19.850Z

Reserved: 2025-01-15T19:34:32.801Z

Link: CVE-2025-0505

cve-icon Vulnrichment

Updated: 2025-05-08T18:56:16.147Z

cve-icon NVD

Status : Received

Published: 2025-05-08T19:16:01.320

Modified: 2025-05-08T19:16:01.320

Link: CVE-2025-0505

cve-icon Redhat

No data.