Vulnerability Details
Basic Information
| Title | CVE-2025-0505 On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain admin privileges on the CloudVision system, with more permissions than necessary, which can be used to query or manipulate system state |
|---|---|
| Type | cve |
| Published | 2025-05-08T18:37:13 |
| Last Seen | 2025-05-08T19:16:54 |
| CVSS Score | 10.0 (CRITICAL) |
CVSS v3 Details
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | CHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | NONE |
CVE Information
| CVE IDs | CVE-2025-0505 |
|---|---|
| CWE | CWE-269 |
| Bulletin Family | cve |
Description
On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain admin privileges on the CloudVision system, with more permissions than necessary, which can be…
Impact Assessment
| Base Score | 10.0 |
|---|---|
| Severity | CRITICAL |