Security Advisory 0188
Summary
| CVE | CVE-2026-101153 |
|---|---|
| State | PUBLISHED |
| Assigner | Arista |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-10-06 20:17:09 UTC |
| Updated | 2026-10-07 13:38:48 UTC |
| Description | On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vulnerability exists. An authenticated user with sufficient high privileges could exploit this to extract unintended data from the Sensor. |
Risk And Classification
Primary CVSS: v4.0 7.2 HIGH from [email protected]
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-22 | CWE-22 CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 7.2 | HIGH | CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/C... |
| 4.0 | CNA | CVSS | 7.2 | HIGH | CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H |
| 3.1 | [email protected] | Secondary | 8 | HIGH | CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 8 | HIGH | CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
CVSS v4.0 Breakdown
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Arista Networks | CloudVision Portal | affected 2026.2.0 custom | CloudVision Portal, virtual appliance or physical appliance |
| CNA | Arista Networks | CloudVision Portal | affected 2026.1.0 2026.1.2 custom | CloudVision Portal, virtual appliance or physical appliance |
| CNA | Arista Networks | CloudVision Portal | affected 2025.3.0 2025.3.3 custom | CloudVision Portal, virtual appliance or physical appliance |
| CNA | Arista Networks | CloudVision Portal | affected 2025.2.0 2025.2.3 custom | CloudVision Portal, virtual appliance or physical appliance |
| CNA | Arista Networks | CloudVision Portal | affected 2025.1.0 2025.1.4 custom | CloudVision Portal, virtual appliance or physical appliance |
| CNA | Arista Networks | CloudVision Portal | affected 2024.3.0 2024.3.3 custom | CloudVision Portal, virtual appliance or physical appliance |
| CNA | Arista Networks | CloudVision Sensor | affected 1.4.0 1.4.2 custom | CloudVision Sensor |
| CNA | Arista Networks | CloudVision Sensor | affected 1.3.0 1.3.1 custom | CloudVision Sensor |
| CNA | Arista Networks | CloudVision Sensor | affected 1.0.0 1.3.0 custom | CloudVision Sensor |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.arista.com/en/support/advisories-notices/security-advisory/24804-securit... | [email protected] | www.arista.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Additional Advisory Data
Solutions
CNA: CVE-2026-101153 has been fixed in the following releases: CloudVision Portal: - 2026.2.1 and later releases in the 2026.2.x train - 2026.1.3 and later releases in the 2026.1.x train CloudVision Sensor: - 1.4.3 and later releases in the 1.4.x train
Workarounds
CNA: There is no reliable mitigation other than stopping the sensor component completely, which would prevent all functionality dependent on it from working. To stop the sensor, execute the following command on the CloudVision or Sensor VM: # Stop sensor completely: cvpi stop sensor To undo this and to start the sensor again use: # Start sensor: cvpi start sensor