Story thread · 6 reports / 6 sources

Arista patches maximum severity vulnerability that is already being exploited

networkworld.com · 13d

Arista patches maximum severity vulnerability that is already being exploited

How the coverage leans

Across 6 sources · syndicated copies counted once

Arista has patched a VeloCloud Orchestrator (VCO) security hole that has been actively leveraged in the wild, one that the vendor says “may allow a remote attacker to access privileged internal functionality and impact the VCO host.” The Arista security advisory added that the hole “may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.” Furthermore, it said, “there is no configuration that can prevent the exposure.” The company advised customers with the affected software, VeloCloud Orchestrator On-Prem (formerly VeloCloud Orchestrator by Broadcom), to upgrade to a fixed release as soon as possible: VCO 5.2.3.14 and later in the 5.2 train, VCO 6.1.3.4 and later in the 6.1 train, or VCO 6.4.2.4 and later in the 6.4 train. It also said that, because compromises to the VCO platform could give attackers access to VeloCloud Edge devices, organizations should consider other incident response activities such as credential rot

First report: Arista patches VeloCloud Orchestrator zero-day exploited in attacks bleepingcomputer.com, 14d

The coverage

  1. Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock

    theregister.com · 14d

  2. Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day

    securityweek.com · 14d

The conversation · 0

Sign in to join the conversation.

No comments yet — start the thread.