Impact
The VeloCloud Edge update workflow allows installation of software bundles without properly validating their signatures because the digest algorithm used for artifact verification is not restricted, a weakness that falls under CWE-347. As a result, an attacker who can upload packages to VeloCloud Orchestrator or who has credentials that provide direct access to an Edge device can install unauthorized software. The CVE description does not explicitly state the outcome, but the ability to install arbitrary software suggests the potential for remote code execution, an effect that is inferred from the vulnerability’s nature.
Affected Systems
Arista Networks VeloCloud Edge software. No specific version information is provided in the advisory, so all releases of VeloCloud Edge in supported branches that have not yet applied the fix are potentially affected.
Risk and Exploitability
The CVSS score of 7.5 indicates a moderate to high severity vulnerability. The EPSS score is less than 1%, implying a low probability of active exploitation. The vulnerability is not listed in the CISA KEV catalog. The path to exploitation requires either privileged upload rights to the Orchestrator or direct administrative credentials to an Edge device, after which the attacker can push and install a malicious bundle through the update workflow.
OpenCVE Enrichment