{"id":16757,"date":"2026-09-24T13:38:29","date_gmt":"2026-09-24T13:38:29","guid":{"rendered":"https:\/\/newestek.com\/?p=16757"},"modified":"2026-09-24T13:38:29","modified_gmt":"2026-09-24T13:38:29","slug":"on-prem-velocloud-orchestrator-under-attack-only-some-versions-patched","status":"publish","type":"post","link":"https:\/\/newestek.com\/?p=16757","title":{"rendered":"On-prem VeloCloud Orchestrator under attack, only some versions patched"},"content":{"rendered":"<div>\n<div id=\"remove_no_follow\">\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<section class=\"wp-block-bigbite-multi-title\">\n<div class=\"container\"><\/div>\n<\/section>\n<p class=\"wp-block-paragraph\">A flaw in VeloCloud Orchestrator enables attackers to access the platform organizations use to manage their <a href=\"https:\/\/www.networkworld.com\/article\/4199622\/arista-debuts-unified-sd-wan-edge-platform.html\">VeloCloud SD-WAN<\/a> subscriptions and the edge devices it controls.<\/p>\n<p class=\"wp-block-paragraph\">Arista, which now owns the VeloCloud business, warned customers that a vulnerable configuration exists in on-premises VeloCloud Orchestrator deployments that remote attackers may abuse to access \u201cprivileged internal functionality\u201d and impact the VSO host. The flaw also affected Arista\u2019s Hosted and Dedicated VCO deployments, but the company has now patched them.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThis issue was discovered externally and is known to be actively exploited,\u201d Arista said in its <a href=\"https:\/\/www.arista.com\/en\/support\/advisories-notices\/security-advisory\/24765-security-advisory-0183\" target=\"_blank\" rel=\"noreferrer noopener\">advisory<\/a>, urging customers to upgrade to a patched release of VCO immediately \u2014 although fixes are currently available only for some of the affected versions.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/mayureshdani\" target=\"_blank\" rel=\"noreferrer noopener\">Mayuresh Dani<\/a>, security research manager, at Qualys Threat Research Unit, warned that unpatched versions remain \u201cexposed to active exploitation and have only compensating controls as a protection.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Arista said that organizations suspecting compromise should preserve VCO web access logs, backend application logs, system logs, database logs, and relevant file-system timestamps before remediation where operationally feasible.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.attackiq.com\/research\/#:~:text=Andrew%20Costis,-Eng.%20Manager%2C%20Adversary\" target=\"_blank\" rel=\"noreferrer noopener\">Andrew Costis<\/a>, engineering manager of the adversary research team at AttackIQ, backs that advice. \u201cPatching closes the door but doesn\u2019t reverse what came through it. A compromised orchestrator can reach the Edge devices it manages, rotate credentials and validate device state across sites,\u201d he said.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Exploitation limited to a configuration<\/h2>\n<p class=\"wp-block-paragraph\">Arista is tracking the flaw as <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-93952\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2026-93952<\/a>, an improper input validation issue with a critical CVSS rating of 10.0.<\/p>\n<p class=\"wp-block-paragraph\">An attack will only work under certain conditions, though: A VCO deployment is exposed only if certificate-based authentication from the VeloCloud Edge to VeloCloud Orchestrator (VCO) is configured, and the attacker has the public key of the VeloCloud Edge authentication certificate and also network access to the VCO web interface. Attackers do not need VCO tenant or operator credentials.<\/p>\n<p class=\"wp-block-paragraph\">\u201cBased on the information available, this is most certainly a cross-site request forgery (<a href=\"https:\/\/www.csoonline.com\/article\/520886\/application-security-threat-watch-cross-site-request-forgery-csrf.html\">CSRF<\/a>) vulnerability that allows threat actors to use an Edge certificate to bypass the front-end and forward the request to internal services, which inherently trusts this information,\u201d Dani said.<\/p>\n<p class=\"wp-block-paragraph\">The affected versions span four VCO release trains: 5.2.3.15 and earlier in the 5.2.x train, 6.1.3.7 and earlier in 6.1.x, 6.4.2.7 and earlier in 6.4.x, and 7.0.0.2 and earlier in 7.0. x.<\/p>\n<p class=\"wp-block-paragraph\">Arista has released fixes in VCO versions 5.2.3.16 and later in the 5.2.3 train and 6.4.2.8 and later in the 6.4.2 train.<\/p>\n<p class=\"wp-block-paragraph\">Fixes for the others trains are still to come.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>What defenders can do<\/h2>\n<p class=\"wp-block-paragraph\">For organizations that cannot immediately upgrade, Arista recommends restricting access to the VCO web interface to trusted administrative networks and monitoring for suspicious activities including known malicious source IPs, unexpected outbound network activity, backdoor daemons and webshells, and unexpected admin changes.<\/p>\n<p class=\"wp-block-paragraph\">\u201cBecause successful exploitation may compromise the orchestrator host and data managed by the orchestrator, operators should follow incident-response guidance appropriate for their deployment,\u201d the company added.<\/p>\n<p class=\"wp-block-paragraph\">The advisory also shared a few indicators of compromise, including a suspicious \u201cvc-sysmond\u201d file, the \u201cx-vc-opt \u201c HTTP header and two source IP addresses associated with exploitation activity.<\/p>\n<p class=\"wp-block-paragraph\">AttackIQ\u2019s Costis said Arista\u2019s advice underlined the need for continuous threat exposure management and adversarial exposure validation: \u201cKnowing which orchestrators are reachable, and proving your access restrictions actually hold, is worth far more before an advisory like this lands than after.\u201d<\/p>\n<p class=\"wp-block-paragraph\">This is the second maximum-severity VeloCloud flaw that Arista has had to patch this year. The company patched <a href=\"https:\/\/www.csoonline.com\/article\/4202502\/arista-patches-maximum-severity-vulnerability-that-is-already-being-exploited.html\">another actively exploited bug<\/a> in the platform in July.<\/p>\n<p class=\"wp-block-paragraph\"><em>This article first appeared on <\/em><a href=\"https:\/\/www.networkworld.com\/article\/4226139\/on-prem-velocloud-orchestrator-under-attack-only-some-versions-patched.html\">Network World<\/a><em>.<\/em><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A flaw in VeloCloud Orchestrator enables attackers to access the platform organizations use to manage their VeloCloud SD-WAN subscriptions and the edge devices it controls. Arista, which now owns the VeloCloud business, warned customers that a vulnerable configuration exists in on-premises VeloCloud Orchestrator deployments that remote attackers may abuse to access \u201cprivileged internal functionality\u201d and impact the VSO host. The flaw also affected Arista\u2019s Hosted&#8230; <\/p>\n<p class=\"more\"><a class=\"more-link\" href=\"https:\/\/newestek.com\/?p=16757\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-16757","post","type-post","status-publish","format-standard","hentry","category-uncategorized","is-cat-link-borders-light is-cat-link-rounded"],"_links":{"self":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16757","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16757"}],"version-history":[{"count":0,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16757\/revisions"}],"wp:attachment":[{"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16757"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16757"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16757"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}