Arista patches maximum severity vulnerability that is already being exploited

Summary

Arista has released patches for a critical vulnerability in its VeloCloud Orchestrator (VCO) that allows remote attackers to access privileged internal functionality and impact the VCO host. The vulnerability, described as a "CISO day wrecker" with a CVSS score of 10.0, is already being actively exploited in the wild and has no configuration workaround.

IFF Assessment

FOE

The article details a critical vulnerability that is actively being exploited and allows attackers to gain control of network orchestrators and connected devices, posing a significant threat to defenders.

Severity

10.0 Critical

The article explicitly states the vulnerability is a 'CVSS-10, unauthenticated command-injection flaw,' indicating a perfect score due to its unauthenticated nature, exploitability, and severe impact on confidentiality, integrity, and availability.

Defender Context

This vulnerability highlights the critical need for organizations to promptly patch their Arista VeloCloud Orchestrators, as it is actively being exploited. Defenders should prioritize incident response activities, including credential rotation and reviewing administrator actions, to mitigate potential compromises. This incident underscores the importance of treating network orchestration platforms as high-value targets for attackers.

Read Full Story →