{
  "document": {
    "category": "security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "publisher": {
      "category": "vendor",
      "contact_details": "support@arista.com",
      "name": "Arista PSIRT",
      "namespace": "https://www.arista.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Security advisory 188 canonical URL",
        "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24804-security-advisory-0188"
      }
    ],
    "title": "Security Advisory 188",
    "tracking": {
      "current_release_date": "2026-10-05T20:27:47Z",
      "generator": {
        "engine": {
          "name": "Arista Networks SecEng Service CSAF Generator"
        }
      },
      "id": "Arista Networks Security Advisory 188",
      "initial_release_date": "2026-10-05T20:27:47Z",
      "revision_history": [
        {
          "date": "2026-10-05T20:27:47Z",
          "number": "1",
          "summary": "Document created"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "CloudVision Portal version 1.4.3",
                    "product": {
                      "name": "CloudVision Portal version 1.4.3",
                      "product_id": "CSAFPID-1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "CloudVision Portal version 2026.2.1",
                    "product": {
                      "name": "CloudVision Portal version 2026.2.1",
                      "product_id": "CSAFPID-0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "CloudVision Portal version 2026.3.0",
                    "product": {
                      "name": "CloudVision Portal version 2026.3.0",
                      "product_id": "CSAFPID-2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "CloudVision Portal version 2024.3.0",
                    "product": {
                      "name": "CloudVision Portal version 2024.3.0",
                      "product_id": "CSAFPID-5"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "CloudVision Portal version 2026.1.3",
                    "product": {
                      "name": "CloudVision Portal version 2026.1.3",
                      "product_id": "CSAFPID-4"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "CloudVision Portal version v1.0.0",
                    "product": {
                      "name": "CloudVision Portal version v1.0.0",
                      "product_id": "CSAFPID-3"
                    }
                  }
                ],
                "category": "product_name",
                "name": "CloudVision Portal"
              }
            ],
            "category": "product_family",
            "name": "Software Products"
          }
        ],
        "category": "vendor",
        "name": "Arista Networks, Inc."
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-101153",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1898011"
      },
      "notes": [
        {
          "category": "description",
          "text": "On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vulnerability exists. An authenticated user with sufficient high privileges could exploit this to extract unintended data from the Sensor.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "No specific configuration is required to be vulnerable to this issue. This vulnerability is present in the default configuration of affected releases.",
          "title": "1898011: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-3"
        ],
        "fixed": [
          "CSAFPID-0",
          "CSAFPID-1",
          "CSAFPID-2",
          "CSAFPID-4"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-101153"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in CloudVision Portal version 1.4.3",
          "product_ids": [
            "CSAFPID-1"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in CloudVision Portal version 2026.1.3",
          "product_ids": [
            "CSAFPID-4"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in CloudVision Portal version 2026.2.1",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in CloudVision Portal version 2026.3.0",
          "product_ids": [
            "CSAFPID-2"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in CloudVision Portal version 2024.3.0",
          "product_ids": [
            "CSAFPID-5"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in CloudVision Portal version v1.0.0",
          "product_ids": [
            "CSAFPID-3"
          ]
        },
        {
          "category": "mitigation",
          "details": "There is no reliable mitigation other than stopping the \\`sensor\\` component completely, which would prevent all functionality dependent on it from working. This includes any data sources onboarded on that sensor including related telemetry data, as well as functionality such as Universal Network Observability (UNO) and Multi-Domain Segmentation Services (MSS).\n\nTo stop the sensor, execute the following command on the CloudVision or Sensor VM:\n\n```python\n# Stop sensor completely:\ncvpi stop sensor\n```\n\nTo undo this and to start the sensor again use:\n\n```python\n# Start sensor:\ncvpi start sensor\n```\n\nNote: While the sensor component is stopped, the sensor and its associated data sources will report as \"inactive\" in CloudVision.\n\nThe recommended resolution is to upgrade to a fixed software version. Make sure to start the sensor component before the upgrade."
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.0,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-0",
            "CSAFPID-4",
            "CSAFPID-1",
            "CSAFPID-3",
            "CSAFPID-5",
            "CSAFPID-2"
          ]
        }
      ],
      "title": "CVE-2026-101153"
    }
  ]
}