Impact
Insufficient validation of inputs supplied through the management and configuration workflows of Arista VeloCloud Edge allows an authorized manager to provide values that are interpreted as operating‑system commands. The vulnerability aligns with OS command injection (CWE‑78) and permits command execution at the device’s operating‑system level, potentially compromising the entire Edge device.
Affected Systems
The affected product is Arista Networks’ VeloCloud Edge. The specific software versions are not enumerated in the advisory, but the issue applies to all current releases within a supported branch until a patched version is deployed.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, while the EPSS score of <1% suggests a low probability of exploitation today. The vulnerability requires an account with authorized management or configuration privileges, so an adversary must first gain or possess legitimate credentials. The direct impact is remote code execution on the device. The advisory is not listed in the CISA KEV catalog.
OpenCVE Enrichment