Arista Networks VeloCloud Orchestrator On-Prem是美国Arista Networks公司的一款本地部署的网络编排平台。 Arista Networks VeloCloud Orchestrator On-Prem 5.2.3.14之前版本、6.1.3.4之前版本、6.4.2.4之前版本和7.0.0.1之前版本存在命令注入漏洞,该漏洞源于可能允许远程攻击者访问特权内部功能,成功利用可损害机密性、完整性和可用性。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Arista Networks | VeloCloud Orchestrator On-Prem | 5.2.0< 5.2.3.14 |
affected |
6.1.0< 6.1.3.4 |
affected | ||
6.4.0< 6.4.2.4 |
affected | ||
7.0.0< 7.0.0.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Arista Networks | VeloCloud Orchestrator On-Prem | 5.2.0 ~ 5.2.3.14 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-17191 | 9.1 CRITICAL | VeloCloud Orchestrator Flow Metrics API SQL Injection |
| CVE-2026-17192 | 8.5 HIGH | VeloCloud Orchestrator Missing Input Validation SSRF |
No comments yet