协调器(orchestrator)的 API 组件中存在输入验证漏洞。经过身份验证的用户可利用此缺陷操纵后端查询,可能导致越权访问超出其预期权限的数据,并引发底层系统发起非预期的出站网络连接。 该问题由 Arista 内部发现,目前该公司未获悉在客户网络中存在针对此问题的恶意利用行为。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Arista Networks | VeloCloud Orchestrator On-Prem | 5.2.0< 5.2.3.14 |
affected |
6.1.0< 6.1.3.4 |
affected | ||
6.4.0< 6.4.2.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Arista Networks | VeloCloud Orchestrator On-Prem | 5.2.0 ~ 5.2.3.14 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-16812 | 10.0 CRITICAL | VeloCloud Orchestrator OS Command Injection |
| CVE-2026-17192 | 8.5 HIGH | VeloCloud Orchestrator Missing Input Validation SSRF |
No comments yet