Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day

Summary

A critical operating system command injection vulnerability in Arista's VeloCloud Orchestrator is being exploited as a zero-day. The flaw allows attackers to gain access to privileged internal functionality within on-premises deployments.

IFF Assessment

FOE

This vulnerability allows attackers to compromise internal systems, posing a direct threat to defenders.

Severity

9.8 Critical (AI Estimated)

The CVSS score is estimated to be high (9.8) due to the critical nature of OS command injection, allowing for potentially full system compromise, privileged access, and exploitation in the wild as a zero-day.

Defender Context

This zero-day exploitation highlights the critical need for organizations to maintain up-to-date security measures and patching for network infrastructure devices. Defenders should prioritize patching or mitigating this Arista VeloCloud Orchestrator vulnerability and remain vigilant for any signs of compromise within their environments.

Read Full Story →