Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day
Summary
A critical operating system command injection vulnerability in Arista's VeloCloud Orchestrator is being exploited as a zero-day. The flaw allows attackers to gain access to privileged internal functionality within on-premises deployments.
IFF Assessment
This vulnerability allows attackers to compromise internal systems, posing a direct threat to defenders.
Severity
The CVSS score is estimated to be high (9.8) due to the critical nature of OS command injection, allowing for potentially full system compromise, privileged access, and exploitation in the wild as a zero-day.
Defender Context
This zero-day exploitation highlights the critical need for organizations to maintain up-to-date security measures and patching for network infrastructure devices. Defenders should prioritize patching or mitigating this Arista VeloCloud Orchestrator vulnerability and remain vigilant for any signs of compromise within their environments.