
[CIVN-2026-0384] Command Injection Vulnerability in Arista
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Command Injection Vulnerability in Arista
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
Arista VeloCloud Orchestrator (VCO) On-Prem 5.2.x releases prior to 5.2.3.14
Arista VeloCloud Orchestrator (VCO) On-Prem 6.1.x releases prior to 6.1.3.4
Arista VeloCloud Orchestrator (VCO) On-Prem 6.4.x releases prior to 6.4.2.4
Arista VeloCloud Orchestrator (VCO) On-Prem 7.0.x releases prior to 7.0.0.1
Overview
A vulnerability has been reported in Arista VeloCloud Orchestrator (VCO) On-Prem which could allow a remote, unauthenticated attacker to execute arbitrary commands, leading to unauthorized access and complete compromise of the targeted system.
Target Audience:
All organizations and individuals using affected versions of Arista products.
Risk Assessment:
Critical risk of remote code execution, unauthorized access and complete system compromise.
Impact Assessment:
Potential for complete compromise of the affected system, unauthorized access, and loss of confidentiality, integrity and availability.
Description
Arista VeloCloud Orchestrator (VCO) On-Prem is a centralized management platform used to configure, monitor and manage VeloCloud SD-WAN deployments.
A command injection vulnerability has been reported in Arista VCO On-Prem due to improper neutralization of special elements used in an operating system command. The vulnerability exposes privileged internal functionality intended only for internal use, which is remotely accessible through the VCO web interface. A remote attacker could exploit this vulnerability by sending crafted requests.
Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary commands, leading to unauthorized access and complete compromise of the targeted system.
Solution
Apply appropriate updates as mentioned as mentioned by the Vendor:
https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144
Vendor Information
Arista Networks
https://www.arista.com/en/support/advisories-notices
References
https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144
CVE Name
CVE-2026-16812
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpssTUACgkQ3jCgcSdc
ys9lVw/+LQ1MqB2zFA96xJr6S+09pF8Y8OO3QuFtnltlrSHESmkNRc/XXbsDiaI5
VB0jcdDCSUxSPxYVYngLTYCiWBEaChx05C+IGiv2pBr3o4Q2MWnNWCnPDxj8rtND
PYdLTSqAV3DSSwyYQD2bIrzUs4IbLWqRmuFc8MrFi8swUmTNBm61W7Iz6twKfpxh
3cpsPMtxwOc0P04oYLr6ALCLCyHQxmphVN5uaBFocHIJtkw4fpC9M1IVUGFDYsgQ
Zo/25e5Cvh5LmvbnT8TVRY2q+gYnT8mZe0zpDKQ7V3lrzdbY0pFH3ZpurT/3vZyG
khc+9s3nbcBzswv59WFD7NdtAuxAR4Zr7O3DruDsWxYkJGulNIH73gtle9AcUheI
o0KjiSIEHjuXjpHZwyjYosBEdk5v5EhI0MOqdWVqh3e6AVBgtPNdBRfjZiZT3z5A
DDZU8uNWSiePrhA59F/b4gudi8uR6CjpT/CxVKqUf2mbGprDbJrg6nYLMKe4OaiS
/yFCOmFBcQNqtnNpEQFpOdCTlH3hnbZm+AlwY7CG9QGwvFgCwscsUFJXK/H1AvDD
igCpbzzXcq4fwgXnV94YXIJN64eYdIfVfgOB0hucClJ68zWdVk9PeO9GVtxWWjyo
3rE0MVAwV0zXjWEW1zTriaxR1Rtid0bKFy9Ao0MpKCMx4lV2/KE=
=1ARR
—–END PGP SIGNATURE—–


