Horizon Alert
Summary of the vulnerability and why it matters
A security vulnerability has been identified in on-premises VeloCloud Orchestrator software, which could allow unauthorized remote access to critical internal functions, potentially impacting the orchestrator's host and the data it manages. Hosted versions have been patched, but on-premises deployments require attention to confirm their exposure and implement necessary actions.
- Unauthorized remote access to core functions.
- Affects on-premises network management software.
- Confirm relevance and exposure for on-premises systems.
Attack Path
How an attacker could exploit the issue
An attacker can reach a vulnerable VeloCloud Orchestrator over the network without needing any prior access. The attacker would interact with a specific, but unspecified, feature of the orchestrator to trigger the vulnerability. If successful, this could allow them to access privileged functions and affect the orchestrator itself and the data it manages.
- Entry condition: Network access required.
- Trigger point: Interaction with a specific feature.
- Resulting risk: Compromise of orchestrator and data.
Live Threat
Current exploitation, exposure, and threat context
A remote attacker could potentially access privileged functionality and impact the VeloCloud Orchestrator (VCO) host. This could lead to compromised confidentiality, integrity, and availability of the orchestrator and its managed data when supported by the advisory's conditions.
- Orchestrator and managed data at risk.
- Remote access to privileged functionality.
- Compromise of confidentiality, integrity, availability.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Arista VeloCloud Orchestrator (VCO) on-prem deployments are the primary concern, as hosted versions have already been patched. Infrastructure and security teams should first identify all VCO instances, determine their exposure and criticality, and locate the accountable owner for remediation planning.
- Infrastructure and security teams own this.
- Verify all on-prem VCO instances.
- Plan remediation based on risk exposure.