Description
An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions without verification. This could result in elevated command execution on Edge units where HA is enabled.
Published: 2026-09-16
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Elevated command execution on VeloCloud Edge
Action: Immediate Patch
AI Analysis

Impact

An actor with network access to the private High Availability (HA) interconnect can trigger sensitive HA peer functions without any authentication. This allows the attacker to elevate privileges and execute commands on the Edge units, effectively gaining full control of the device. The weakness is a missing authentication check, resulting in a privilege escalation vulnerability.

Affected Systems

The vulnerability affects Arista Networks VeloCloud Edge firmware releases 5.2.7.0 or later in the 5.2.x train, 6.1.5.0 or later in the 6.1.x train, 6.4.2 or later in the 6.4.x train, and 7.0.0 or later. All Edge units that have HA enabled and use the default HA interconnect configuration are impacted.

Risk and Exploitability

The CVSS score of 8.7 classifies this as high severity, while the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog, but the lack of authentication makes it attractive for internal or compromised network actors. Exploitation requires only network access to the private HA interconnect; no additional credentials are needed.

Generated by OpenCVE AI on September 18, 2026 at 10:47 UTC.

Remediation

Vendor Solution

The following VeloCloud Edge releases contain the fix: - 5.2.7.0 and later in the 5.2.x train - 6.1.5.0 and later in the 6.1.x train - 6.4.2 and later in the 6.4.x train - 7.0.0 and later No hotfixes are available for this issue.


Vendor Workaround

Use dedicated port-to-port connections between HA pairs. Avoid extending the HA interconnect through shared switches or VLANs. Restrict physical and network access to HA interfaces.


OpenCVE Recommended Actions

  • Upgrade the firmware to any VeloCloud Edge release that contains the fix, such as 5.2.7.0 or later, 6.1.5.0 or later, 6.4.2 or later, or 7.0.0 or later.
  • Configure dedicated port‑to‑port connections between HA pairs and ensure the HA interconnect does not traverse shared switches or VLANs.
  • Restrict physical and network access to the HA interfaces to prevent unauthorized actors from reaching the private HA interconnect.

Generated by OpenCVE AI on September 18, 2026 at 10:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Arista
Arista velocloud Edge
Vendors & Products Arista
Arista velocloud Edge

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Description An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions without verification. This could result in elevated command execution on Edge units where HA is enabled.
Title Security Advisory 0179
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Arista Velocloud Edge
cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-16T17:53:47.977Z

Reserved: 2026-09-05T01:54:43.258Z

Link: CVE-2026-86106

cve-icon Vulnrichment

Updated: 2026-09-16T17:53:43.230Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T11:16:43.783

Modified: 2026-09-16T20:36:52.890

Link: CVE-2026-86106

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T11:00:09Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function