Arista Networks has issued an emergency security update to address a critical zero-day vulnerability in its VeloCloud Orchestrator (VCO) On-Prem deployments, which the company confirms is being actively exploited by attackers. The flaw presents a maximum-severity risk to organizations relying on the SD-WAN control plane, prompting an urgent call for immediate patching.

According to an advisory published by Arista and covered by BleepingComputer, the vulnerability allows a remote, unauthenticated attacker to gain administrative control over affected VeloCloud Orchestrator instances. The vulnerability, assigned a CVSS v3 score of 10.0, the highest possible rating, could enable an attacker to execute arbitrary code, exfiltrate sensitive configuration data, or disrupt the entire network fabric managed by the orchestrator.

The vulnerability affects VeloCloud Orchestrator (VCO) On-Prem deployments. The VCO is the centralized management component of VMware's (now Broadcom's) VeloCloud SD-WAN solution, responsible for orchestrating policies, configurations, and analytics across all connected edge devices. A compromise of this component is particularly severe, as it effectively gives an attacker the keys to the kingdom for the entire SD-WAN infrastructure.

Arista's advisory states that the issue has been patched in the following versions: * VCO On-Prem 5.4.2 and later * VCO On-Prem 6.2.2 and later

The company has not disclosed detailed technical specifics about the vulnerability's root cause or the observed exploitation campaigns, a common practice to prevent wider abuse before patches are widely applied. However, the active exploitation status confirms that threat actors are already aware of and leveraging this flaw.

Given the severity and confirmed exploitation, network and infrastructure administrators are advised to take immediate action. The primary mitigation is to upgrade the VeloCloud Orchestrator software to the patched versions specified in Arista's advisory. Organizations should prioritize this patching effort as a critical security task.

For environments that cannot immediately apply the update, the advisory recommends restricting network access to the VCO management interface, allowing connections only from trusted internal administrative networks. This network segmentation can help reduce the attack surface while the patching process is underway.

This incident underscores the persistent security risks associated with centralized network management planes, particularly as SD-WAN adoption continues to grow. The consolidation of control within orchestrators like VCO creates high-value targets for attackers seeking widespread network access or data theft. The rapid release of this emergency patch highlights the critical importance of maintaining vigilant vulnerability management and having robust update procedures for core network infrastructure.


Arista Networks已發布緊急安全更新,以修補其VeloCloud Orchestrator (VCO) 本地部署版本中的一個關鍵零日漏洞。該公司確認該漏洞正遭攻擊者活躍利用。此漏洞對依賴該SD-WAN控制平面的機構構成最高級別風險,促使公司緊急呼籲立即進行修補。

根據Arista發佈的公告(由BleepingComputer報導),該漏洞允許一個遠端、未獲認證的攻擊者取得受影響VeloCloud Orchestrator實例的管理控制權。該漏洞被賦予CVSS v3 10.0分(最高可能評級),可能使攻擊者能夠執行任意代碼、竊取敏感配置數據,或中斷由協調器管理的整個網絡結構。

該漏洞影響VeloCloud Orchestrator (VCO) 本地部署版本。VCO是VMware(現屬Broadcom)VeloCloud SD-WAN解決方案的集中管理組件,負責協調所有已連接邊緣設備的策略、配置和分析。該組件遭入侵尤其嚴重,因為它實際上賦予了攻擊者進入整個SD-WAN基礎設施的「鑰匙」。

Arista的公告指出,該問題已在以下版本中得到修補: * VCO On-Prem 5.4.2及更高版本 * VCO On-Prem 6.2.2及更高版本

該公司尚未披露有關漏洞根本原因或已觀察到的利用活動的詳細技術細節,這是在補丁廣泛應用前為防止更廣泛濫用的常見做法。然而,漏洞被活躍利用的狀態證實威脅行為者已知曉並正在利用此缺陷。

鑑於其嚴重性及已確認的利用情況,建議網絡及基礎設施管理員立即採取行動。首要緩解措施是將VeloCloud Orchestrator軟件升級至Arista公告中指定的修補版本。各機構應將此次修補工作作為關鍵安全任務優先處理。

對於無法立即應用更新的環境,該公告建議限制對VCO管理介面的網絡訪問,僅允許來自受信內部管理網絡的連接。這種網絡分段有助於在修補過程中減少攻擊面。

此事件突顯了與集中式網絡管理平面相關的持續性安全風險,尤其是在SD-WAN採用率持續增長的背景下。將控制權集中於VCO等協調器,會為尋求廣泛網絡訪問或數據竊取的攻擊者創造高價值目標。此次緊急補丁的快速發佈凸顯了保持警惕的漏洞管理以及為核心網絡基礎設施制定健全更新流程的至關重要性。

新聞來源 / Original News Source