{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-22T14:25:26.670","vulnerabilities":[{"cve":{"id":"CVE-2025-0505","sourceIdentifier":"psirt@arista.com","published":"2025-05-08T19:16:01.320","lastModified":"2026-04-15T00:35:42.020","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain admin privileges on the CloudVision system, with more permissions than necessary, which can be used to query or manipulate system state for devices under management. Note that CloudVision as-a-Service is not affected."},{"lang":"es","value":"En los sistemas Arista CloudVision (implementaciones locales virtuales o físicas), el aprovisionamiento sin intervención permite obtener privilegios de administrador en el sistema CloudVision, con más permisos de los necesarios, lo que permite consultar o manipular el estado del sistema de los dispositivos administrados. Tenga en cuenta que CloudVision como servicio no se ve afectado."}],"metrics":{"cvssMetricV31":[{"source":"psirt@arista.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N","baseScore":10.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.8}]},"weaknesses":[{"source":"psirt@arista.com","type":"Secondary","description":[{"lang":"en","value":"CWE-269"}]}],"references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/21315-security-advisory-0115","source":"psirt@arista.com"}]}}]}