CVE-2026-93952: Arista VeloCloud Orchestrator
Arista VeloCloud Orchestrator (VCO) on-prem bevat een onjuiste input validatie kwetsbaarheid die een remote aanvaller in staat kan stellen om toegang te krijgen tot bevoorrechte interne functionaliteit en impact op de VCO host. Succesvolle exploitatie kan afbreuk doen aan de vertrouwelijkheid, integriteit en beschikbaarheid van de orkestmeester en gegevens die door de orkestmeester worden beheerd.
CISA (English)
Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
- Leverancier
- Arista
- Product
- VeloCloud Orchestrator
- Kwetsbaarheid
- Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
- Toegevoegd op
- 22 sep 2026
- CISA-termijn (Amerikaanse federale instanties)
- 25 sep 2026
- Bekend gebruik in ransomwarecampagnes
- Onbekend
- Zwakte (CWE)
- CWE-20
Referenties
Laatst bijgewerkt: · Catalogusversie 2026.10.02