Arista has patched a VeloCloud Orchestrator (VCO) security hole that has been actively leveraged in the wild, one that the vendor says “may allow a remote attacker to access privileged internal functionality and impact the VCO host.”
The , group VP for security at IDC, described the hole as a “CISO day wrecker.”
“This is the rare kind of perfect 10 that you never want to see: an unauthenticated command-injection flaw that’s already being exploited in the wild is what CISO have nightmares about,” Dickson said. “To make things worse, there’s no configuration workaround because the VCO web interface is exposed by default.”
Consultant , principal consultant at Digital 520, added, “A management plane that an unauthorized stranger can run commands on is close to the worst-case scenario.”
Concerning questions
reportedly secured its cloud-hosted infrastructure before on-premises deployments, highlighting a harsh reality that organizations that choose on-prem for compliance, sovereignty, or control often face slower access to critical security fixes during active exploitation,” he said. And because many enterprises unknowingly leave VCO management interfaces internet-accessible for use by vendors and integrators, this turns a single vulnerability into a potential enterprise-wide compromise.
He added that patch management in this case may be tricky. “The patch could be a difficult operational challenge for mature organizations that rely on SD-WAN automation through tools such as Ansible and Terraform. Any change to backend command execution may disrupt existing workflows.”
A familiar failure
The consultants and analysts also highlighted Arista’s statement that the functionality being compromised “was intended to be for internal use only and is not intended to be remotely accessible.”
‘Not intended to be remotely accessible’ isn’t the same as ‘not remotely accessible,’ IDC’s Dickson said. “This is a textbook case of internal functionality that was never actually sufficiently walled off from the exposed interface, which is why a single unauthenticated request could reach it.”
Kenney added the internal-only mindset is not only dangerous now, but is going to be increasingly so now that attackers have discovered the weakness.
“What happened here is a familiar failure,” he said. “Someone writes an internal function and assumes the only thing calling it will be another trusted part of the system, so they don’t sanitize the input the way they would on a public endpoint, because the caller is supposed to be you.” But then, he said, at some point, a change leaves the endpoint reachable from outside, and now a stranger is feeding input to a function written to trust whoever called it. “The code never changed. Its exposure did,” he said.
It was the outcome of a pair of colliding decisions, Kenney said. “’This is internal. It doesn’t need hardening’ was fine when it was made and ‘this has to be reachable for the product to work’ was also fine. But nobody went back and checked whether the first was still true after the second happened.”
Arista declined a request for more information, saying in an email, “We have no comment beyond what is publicly available in the published CVE.”
M&A blues
Another factor that may have played a role in this situation is that VeloCloud is .
SOCIAL SHARE CARD GENERATOR