DEV Community

Cover image for Arista Patches Critical VeloCloud Orchestrator Zero-Day Under Active Attack
BeyondMachines for BeyondMachines

Posted on • Originally published at beyondmachines.net

Arista Patches Critical VeloCloud Orchestrator Zero-Day Under Active Attack

Summary

Arista Networks released an emergency advisory for a CVSS 10.0 OS command injection vulnerability in VeloCloud Orchestrator On-Prem that is currently being exploited in the wild. The flaw allows unauthenticated attackers to gain full control over the orchestrator and all managed SD-WAN edge devices.

Take Action:

Make sure all VeloCloud Orchestrator On-Prem devices are isolated from the internet and accessible only from trusted administrative networks. Then immediately upgrade to a fixed release (5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1) and block the known malicious IPs (8.19.75.217, 206.72.242.124, 206.72.242.162) at your firewall. After patching rotate all credentials and certificates so attackers can't reuse any potentially stolen data.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)