Impact
This vulnerability is an OS command injection flaw in the VeloCloud Orchestrator (VCO) on‑prem web interface that can be triggered remotely. An attacker who successfully abuses the flaw can execute arbitrary commands with the privileges of the VCO service, gaining full control over the orchestrator host. The result is a compromise of confidentiality, integrity, and availability of the orchestrator and the network data it manages.
Affected Systems
Arista Networks VeloCloud Orchestrator On‑Prem is affected. All VCO releases prior to the listed fixed builds are vulnerable: VCO 5.2 train versions earlier than 5.2.3.14, VCO 6.1 train versions earlier than 6.1.3.4, and VCO 6.4 train versions earlier than 6.4.2.4. Systems on unsupported trains should contact TAC for upgrade guidance.
Risk and Exploitability
The vulnerability scores a CVSS of 10, indicating maximum severity. The EPSS score is < 1%, indicating a very low but non‑zero probability of exploitation. It is known to be actively exploited and is listed in CISA’s KEV catalog. The VCO web interface is intended for internal use and therefore is expected to be trusted, but the flaw exposes it to remote attackers. Exploitation requires sending malicious input to the vulnerable endpoint, resulting in remote execution of arbitrary commands on the host.
OpenCVE Enrichment