🔴 Critical | Source: The Register — Security
Arista Networks has patched a critical unauthenticated command injection vulnerability in its VeloCloud SD-WAN Orchestrator, scoring a perfect CVSS 10.0, which is already being actively exploited in the wild. The flaw allows attackers to execute arbitrary commands without any credentials, potentially compromising managed Edge devices across enterprise networks. CISA has added it to its Known Exploited Vulnerabilities catalogue, giving federal agencies a hard deadline to patch.
Security Architect’s Take: Prioritise emergency patching of all VeloCloud Orchestrator instances immediately — active exploitation means you cannot rely on standard change windows. In the interim, restrict Orchestrator management plane access to trusted IP ranges via firewall rules or VPN, and audit Edge device configurations for signs of unauthorised changes.
Original advisory: Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock