Impact
VeloCloud Orchestrator on‑prem exposes privileged internal functionality that can be accessed by a remote attacker, potentially compromising the confidentiality, integrity, and availability of the orchestrator and the data it manages. The vulnerability enables exploitation that may allow the attacker to gain high‑privilege access and control of the host system.
Affected Systems
Arista Networks VeloCloud Orchestrator (VCO) On‑Prem is affected. All flavors, including Hosted and Dedicated, were impacted. The vulnerability has already been patched by Arista; the correct fix requires upgrading to VCO 5.2.3.16 or later in the 5.2.3 train, or VCO 6.4.2.8 or later in the 6.4.2 train. Systems on unsupported release trains should contact TAC for upgrade options.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.5, reflecting a high severity and the potential for full remote compromise. EPSS data is not available, and the issue is not listed in the CISA KEV catalog. Although the exact attack vector is not explicitly detailed, it is inferred that the web interface is likely the entry point, meaning an attacker may exploit the flaw over the network. The combination of high severity and network reach indicates a significant risk if left unpatched.
OpenCVE Enrichment