Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day

https://www.securityweek.com/wp-content/uploads/2023/10/Zero-Day-Exploit.jpg

Arista Networks on Monday released patches for a critical-severity OS injection vulnerability in the VeloCloud Orchestrator (VCO) centralized management platform, warning that it has been exploited in the wild as a zero-day.

The security defect is tracked as CVE-2026-16812, has a maximum CVSS score of 10, and could be exploited remotely to access privileged functionality intended for internal use only.

“Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator,” Arista Networks notes in its advisory.

According to the company, only VeloCloud Orchestrator On-Prem (formerly VeloCloud Orchestrator by Broadcom) is affected by the bug. The flaw was addressed in VCO versions 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1.

“This issue was discovered externally and is known to be actively exploited,” Arista warned.

The company also pointed out that no special configuration or authentication is required for successful exploitation.

Advertisement. Scroll to continue reading.

...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more