Skip to content

Arista Vulnerability in VeloCloud Orchestrator Actively Exploited

The Bottom Line: A critical, unpatched CVSS 10.0 command injection flaw in VeloCloud Orchestrator is being actively exploited, requiring immediate upgrade to fixed versions and comprehensive incident response measures.

Arista has addressed a critical security vulnerability in VeloCloud Orchestrator On-Prem (CVSS 10.0) that is already being actively exploited in the wild. The unauthenticated command injection vulnerability allows attackers to access privileged functions and can compromise the availability, integrity, and confidentiality of the orchestrator and managed data.

Arista is informing affected customers that an upgrade is required for VeloCloud Orchestrator On-Prem (formerly VeloCloud Orchestrator by Broadcom): at least version 5.2.3.14 for the 5.2 track, 6.1.3.4 for the 6.1 track, or 6.4.2.4 for the 6.4 track. The company emphasizes that “no configuration can prevent exposure” — the web interface is exposed by default and cannot be safely disabled.

Since compromising the VCO orchestrator grants attackers access to all connected VeloCloud Edge devices, Arista recommends organizations, in addition to immediate patching, take additional incident response measures: rotate all credentials, review administrative activities, validate the status of managed devices, and restore or replace affected instances from trusted sources.

Security experts assess the flaw as an extreme case: unauthenticated command injection in a network orchestration platform that is already being exploited, combined with the absence of configuration workarounds. Brian Levine of FormerGov warns that by controlling the management plane, attackers effectively control all connected edge devices — and recommends treating SD-WAN and orchestration platforms as Tier-0 assets and patching them with the same urgency as identity infrastructure.

Giuseppe Trotta of Malwarebytes highlights that Arista secured its cloud-hosted systems before on-premises deployments — a pattern that disadvantages organizations that choose on-premises for compliance or control reasons. Additionally, many enterprises unintentionally expose VCO management interfaces to the internet for vendor and integrator access. Patch management could also become operationally challenging, since changes to backend command execution could disrupt existing automation (Ansible, Terraform).

Arista had stated that the compromised functionality “was intended for internal use only and should not be remotely accessible.” Security consultants point out that this is a classic scenario of internal functions that were never properly isolated from the exposed interface — which is why a simple unauthenticated request could reach them.


Source: www.csoonline.com · Published 29 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: