Arista patches critical command injection flaw in VeloCloud Orchestrator exploited in attacks
Overview
Arista has issued a patch to address a serious command injection vulnerability in its on-premises VeloCloud Orchestrator (VCO). This flaw could allow attackers to execute arbitrary commands on affected systems, potentially leading to unauthorized access and control. Organizations using VeloCloud Orchestrator should prioritize applying this patch to safeguard their networks. The vulnerability has been confirmed to be exploited in the wild, which heightens the urgency for users to update their systems promptly. Failure to address this issue could expose sensitive data and disrupt operations for affected companies.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: VeloCloud Orchestrator (VCO) deployments
- Action Required: Apply the patch released by Arista for the command injection vulnerability.
- Timeline: Newly disclosed
Original Article Summary
As reported by Bleeping Computer, Arista released a patch for a critical command injection vulnerability affecting on-premises VeloCloud Orchestrator (VCO) deployments.
Impact
VeloCloud Orchestrator (VCO) deployments
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Apply the patch released by Arista for the command injection vulnerability.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Vulnerability, Patch, Update, and 2 more.