Story thread · 6 reports / 6 sources
Arista patches maximum severity vulnerability that is already being exploited
networkworld.com · 13d

How the coverage leans
Across 6 sources · syndicated copies counted once
Arista has patched a VeloCloud Orchestrator (VCO) security hole that has been actively leveraged in the wild, one that the vendor says “may allow a remote attacker to access privileged internal functionality and impact the VCO host.” The Arista security advisory added that the hole “may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.” Furthermore, it said, “there is no configuration that can prevent the exposure.” The company advised customers with the affected software, VeloCloud Orchestrator On-Prem (formerly VeloCloud Orchestrator by Broadcom), to upgrade to a fixed release as soon as possible: VCO 5.2.3.14 and later in the 5.2 train, VCO 6.1.3.4 and later in the 6.1 train, or VCO 6.4.2.4 and later in the 6.4 train. It also said that, because compromises to the VCO platform could give attackers access to VeloCloud Edge devices, organizations should consider other incident response activities such as credential rot
First report: Arista patches VeloCloud Orchestrator zero-day exploited in attacks — bleepingcomputer.com, 14d
The coverage
- Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock
theregister.com · 14d
- Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day
securityweek.com · 14d
The conversation · 0
Sign in to join the conversation.
No comments yet — start the thread.