Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock
Summary
Arista has released a patch for a critical vulnerability in its VeloCloud orchestrator software. This bug, identified as CVE-2023-34071, allows for unauthenticated command injection and has a perfect CVSS score of 10.0. CISA has issued a directive, compelling federal agencies to patch this vulnerability by a specific deadline.
IFF Assessment
The discovery and active exploitation of a critical vulnerability in network infrastructure poses a significant threat to organizations relying on these devices for secure operations.
Severity
The CVSS score of 10.0 reflects the critical nature of the vulnerability, allowing unauthenticated command injection which can lead to complete system compromise.
Defender Context
This vulnerability in Arista's VeloCloud orchestrator highlights the ongoing risks associated with network infrastructure security. Defenders must prioritize patching such critical flaws promptly to prevent exploitation, especially when government agencies are also being urged to address the issue.