Arista patches maximum severity vulnerability that is already being exploited

Arista has patched a VeloCloud Orchestrator (VCO) security hole that has been actively leveraged in the wild, one that the vendor says “may allow a remote attacker to access privileged internal functionality and impact the VCO host.”
The Arista security advisory added that the hole “may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.”
Furthermore, it said, “there is no configuration that can prevent the exposure.”
The company advised customers with the affected software, VeloCloud Orchestrator On-Prem (formerly VeloCloud Orchestrator by Broadcom), to upgrade to a fixed release as soon as possible: VCO 5.2.3.14 and later in the 5.2 train, VCO 6.1.3.4 and later in the 6.1 train, or VCO 6.4.2.4 and later in the 6.4 train.
It also said that, because compromises to the VCO platform could give attackers access to VeloCloud Edge devices, organizations should consider other incident response activities such as credential rotation, review of administrator activity, validation of managed device state, and restoration or replacement of affected instances from trusted sources.
About as bad as it gets
Frank Dickson, group VP for security at IDC, described the hole as a “CISO day wrecker.”
“This is the rare kind of perfect 10 that you never want to see: an unauthenticated command-injection flaw that’s already being exploited in the wild is what CISO have nightmares about,” Dickson said. “To make things worse, there’s no configuration workaround because the VCO web interface is exposed by default.”
Consultant Brian Levine, executive director of FormerGov, agreed.
“A CVSS‑10, unauthenticated command‑injection flaw in a network orchestrator is about as bad as it gets. Once an attacker owns the management plane, they effectively own every connected edge device,” he said. “The enterprise implication is straightforward: treat SD‑WAN and orchestration platforms as Tier‑0 assets, restrict their exposure, and patch…