CVE-2020-24333: Arista Cloudvision Portal

Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.

A vulnerability in Arista’s CloudVision Portal (CVP) prior to 2020.2 allows users with “read-only” or greater access rights to the Configlet Management module to download files not intended for access, located on the CVP server, by accessing a specific API.

Affected products

  • Arista Cloudvision Portal: before 2020.2.0 (fixed in 2020.2.0)

Published 2020-09-22. Last modified 2026-06-17.