Horizon Alert
Summary of the vulnerability and why it matters
A critical security issue has been identified in the on-premise VeloCloud Orchestrator that could allow unauthorized remote access to sensitive internal functions, potentially compromising the orchestrator and its managed data. While hosted and dedicated versions have been patched, on-premise installations require attention, especially given that the vulnerability is actively exploited and was discovered externally.
- Unpatched on-premise systems allow remote privileged access.
- Actively exploited vulnerability impacts confidential data.
- Confirm relevance and exposure for on-premise deployments.
Attack Path
How an attacker could exploit the issue
An attacker can reach privileged internal functionality within the VeloCloud Orchestrator by leveraging an unauthenticated network-accessible feature. This functionality, intended only for internal use, can be triggered remotely, potentially leading to a compromise of the orchestrator's confidentiality, integrity, and availability, as well as the data it manages.
- Entry: Unauthenticated network access required.
- Trigger: Remote access to internal functionality.
- Risk: Compromise of orchestrator and data.
Live Threat
Current exploitation, exposure, and threat context
A remote attacker could access privileged internal functionality, potentially impacting the VeloCloud Orchestrator host. This could compromise the confidentiality, integrity, and availability of the orchestrator and the data it manages.
- Orchestrator host and managed data at risk.
- Unauthenticated remote access to internal functions.
- Compromise of orchestrator's confidentiality, integrity, availability.
Operational Fix
Recommended remediation, mitigation, and detection steps
The on-premises VeloCloud Orchestrator (VCO) is impacted by this critical vulnerability, which could allow remote attackers to access privileged internal functions and compromise the orchestrator and its managed data. Given that hosted and dedicated VCO versions have been patched, the immediate priority for on-premises deployments is to identify all instances, confirm their network exposure and business criticality, and engage the accountable owner for remediation planning.
- Identify on-prem VCO instances and owners.
- Verify network exposure and business criticality.
- Plan remediation based on identified risk.