An authenticated Redis session could be used to obtain full root access to all servers in the CVX cluster. Note that this would require an attacker to have both network access to the Redis service on a CVX server and the Redis password. Please note that all Redis communication, including authentication, occurs over plaintext in the present day. TLS support is tracked under RFE1294850.
History

Tue, 09 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 07 Jun 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Arista
Arista cloudvision Exchange
Vendors & Products Arista
Arista cloudvision Exchange

Fri, 05 Jun 2026 16:45:00 +0000

Type Values Removed Values Added
Description An authenticated Redis session could be used to obtain full root access to all servers in the CVX cluster. Note that this would require an attacker to have both network access to the Redis service on a CVX server and the Redis password. Please note that all Redis communication, including authentication, occurs over plaintext in the present day. TLS support is tracked under RFE1294850.
Title Arista CloudVision Exchange (CVX) Cluster Privilege Escalation via MCS Redis Session
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published: 2026-06-05T15:58:15.288Z

Updated: 2026-06-09T14:37:20.098Z

Reserved: 2025-05-22T16:20:16.105Z

Link: CVE-2025-5088

cve-icon Vulnrichment

Updated: 2026-06-09T14:10:09.544Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-05T17:16:29.097

Modified: 2026-06-05T19:03:48.933

Link: CVE-2025-5088

cve-icon Redhat

No data.