VeloCloud Edge 软件更新流程可能接受未经验证签名的更新包,原因是该流程未对用于工件验证的摘要算法进行限制。拥有向 VeloCloud Orchestrator 上传软件包的足够权限,或拥有允许直接访问 Edge 设备的凭证的攻击者,可能借此安装未经授权的软件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Arista Networks | VeloCloud Edge | 6.4.0 ~ 6.4.1.x | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73447 | 9.1 CRITICAL | Security Advisory 0162 - gNSI Certz/Bootz OS Command Injection via Crafted Rotate Request |
| CVE-2026-86108 | 8.0 HIGH | Security Advisory 0181 |
| CVE-2026-73450 | 6.9 MEDIUM | Security Advisory 0161 |
No comments yet