CVE-2026-93952: Arista VeloCloud Orchestrator
Arista VeloCloud Orchestrator (VCO) on-prem含有不適當的輸入驗證弱點,可能讓遠端攻擊者訪問特權的內部功能並影響VCO主機。成功的利用可能損害管弦樂團的保密性、完整性和可獲得性以及管弦樂團管理的資料。
CISA (English)
Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
- 廠商
- Arista
- 產品
- VeloCloud Orchestrator
- 漏洞
- Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
- 加入日期
- 2026年9月22日
- CISA 修補期限(美國聯邦機關)
- 2026年9月25日
- 已知用於勒索軟體攻擊
- 未知
- 弱點(CWE)
- CWE-20
參考資料
本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。
最後更新: · 目錄版本 2026.10.02