Technology newsroom
Urgent alert! A critical-level Zero-Day vulnerability in Arista VeloCloud Orchestrator has been exploited. Administrators should update immediately.
Arista Networks has issued a warning about a critical zero-day vulnerability (CVE-2024-2035) in the on-premises version of VeloCloud Orchestrator, which has already been exploited by hackers. Administrators are advised to update the patch as soon as possible.
π¨ Highest-level alert! Arista VeloCloud Orchestrator has a Zero-Day vulnerability that is currently being actively exploited
π Summary of important points:
- An OS Command Injection vulnerability, CVE-2024-2035, was found in Arista VeloCloud Orchestrator with a Critical severity level (CVSS 9.8)
- Hackers who do not need to authenticate can access the system remotely and take full control of the machine, affecting only the On-Premises version.
- This vulnerability has been discovered to be exploited through a Zero-Day attack. Arista has released a patch, and administrators must update it as soon as possible.
Arista Networks has issued a major security alert regarding a critical vulnerability in the VeloCloud Orchestrator product, which is a platform for managing SD-WAN (Software-Defined Wide Area Network) networks used by many organizations.
The vulnerability, identified by CVE-2024-2035, is an OS command injection type with a critical severity level, having a CVSS score as high as 9.8 out of 10. What is concerning is that this vulnerability does not require authentication to exploit, allowing hackers with access to the Orchestrator network to send dangerous commands and take control of the system immediately.
π Impacts and Risks
Exploiting this vulnerability allows malicious actors to access high-level internal functions of the system, enabling them to run any command on the Orchestrator's operating system. This could lead to theft of critical information, causing the entire network system to crash, or it could be used as a base to penetrate other systems within the organization. Importantly, Arista confirmed that this vulnerability has already been exploited in real attacks (exploited in the wild) before it was discovered and patched, which is known as a Zero-Day attack.
π‘οΈ Correction and Advice
Arista has released a security patch to fix the vulnerability. The recommendation for administrators using Arista VeloCloud Orchestrator in an on-premises setup (installed on the organization's own servers) is to check the version and apply the security patch update immediately according to Arista's instructions, as the risk level is the highest. For customers using the cloud-hosted version, they will not be affected by this vulnerability.
π¬ Does your organization use SD-WAN solutions from Arista? Have you checked and updated the latest security patches yet?