Arista CloudVision Zero Touch Provisioning Privilege Escalation Vulnerability

Vulnerability

A vulnerability exists in Arista CloudVision systems, both virtual and physical on-premise deployments, allowing Zero Touch Provisioning (ZTP) to be exploited for unauthorized admin privileges. This elevated access, which exceeds necessary permissions, could be used to query or manipulate the system state of managed devices. CloudVision as-a-Service is not affected.

Impact

Exploitation of this vulnerability grants unauthorized admin privileges on the affected CloudVision system, allowing for excessive permissions that could be used to alter or query the system state of managed devices.

Remediation

The ZTP component can be disabled by running 'cvpi disable ztp' and 'cvpi stop ztp' on any node of the CloudVision deployment. After upgrading to a remediated version, ZTP can be re-enabled with 'cvpi enable ztp' and 'cvpi start ztp'. For more information on upgrading, consult the Arista CloudVision 2024.3 Help Center.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
5.0
exploitability
7.4
remediation
7.9
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.