VCO 功能未能充分验证由调用方提供的输入,从而导致能够以已认证的租户账户身份向其他情况下无法访问的内部服务发起请求。此漏洞要求至少具备“企业标准管理员”(Enterprise Standard Admin)角色。 该问题由 Arista 内部发现,公司目前未发现任何在客户网络中恶意利用该问题的案例。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Arista Networks | VeloCloud Orchestrator On-Prem | 5.2.0< 5.2.3.14 |
affected |
6.1.0< 6.1.3.4 |
affected | ||
6.4.0< 6.4.2.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Arista Networks | VeloCloud Orchestrator On-Prem | 5.2.0 ~ 5.2.3.14 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-16812 | 10.0 CRITICAL | VeloCloud Orchestrator OS Command Injection |
| CVE-2026-17191 | 9.1 CRITICAL | VeloCloud Orchestrator Flow Metrics API SQL Injection |
No comments yet