Full Report
Arista Networks security advisory (AV26-947)
Analysis Summary
# Vulnerability: Command Injection in VeloCloud Orchestrator (VCO)
## CVE Details
- **CVE ID:** CVE-2026-93952
- **CVSS Score:** Not explicitly listed in the bulletin, but typically rated as **Critical/High** for this product line.
- **CWE:** Not specified (Likely Command Injection or Improper Input Validation)
## Affected Systems
- **Products:** VeloCloud Orchestrator (VCO) On-Prem
- **Versions:**
- 5.2.0 to 5.2.3.15
- 6.1.0 to 6.1.3.7
- 6.4.0 to 6.4.2.7
- 7.0.0 to 7.0.0.2
- **Configurations:** On-Premises deployments of the Orchestrator software.
## Vulnerability Description
While the specific technical root cause is not detailed in the brief advisory, the vulnerability affects the VeloCloud Orchestrator (VCO). Based on the exploitation status and product type, these vulnerabilities generally involve improper validation of user-supplied input, potentially leading to unauthorized command execution or administrative bypass within the management interface.
## Exploitation
- **Status:** **Exploited in the wild** (Active exploitation reported by open-source intelligence).
- **Complexity:** Not specified (Likely Low to Medium).
- **Attack Vector:** Network (Remote).
## Impact
- **Confidentiality:** High (Potential access to network configuration and metadata).
- **Integrity:** High (Potential to modify network policies and device configurations).
- **Availability:** High (Potential to disrupt SD-WAN management and connectivity).
## Remediation
### Patches
Arista Networks recommends upgrading to the following remediated versions or higher:
- **5.x Branch:** Update to version **5.2.3.16** (or later)
- **6.1.x Branch:** Update to version **6.1.3.8** (or later)
- **6.4.x Branch:** Update to version **6.4.2.8** (or later)
- **7.x Branch:** Update to version **7.0.0.3** (or later)
### Workarounds
No specific temporary workarounds were provided in the bulletin. Organizations are urged to prioritize patching due to active exploitation.
## Detection
- **Indicators of Compromise:** Monitor system logs for unusual administrative logins, unauthorized configuration changes, or unexpected outbound traffic from the VCO appliance.
- **Detection methods and tools:** Review VCO audit logs for suspicious commands or API calls originating from unknown IP addresses.
## References
- **Vendor Advisory 0183:** hxxps[://]www[.]arista[.]com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183
- **Arista Security Portal:** hxxps[://]www[.]arista[.]com/en/support/advisories-notices
- **Cyber Centre Bulletin:** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/arista-networks-security-advisory-av26-947