CloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuration mechanisms via the management plane, related to a request to /web/system/console/bundle.
https://www.arista.com/en/support/advisories-notices/security-advisories/2116-security-advisory-27