Affected Systems
Arista VeloCloud Orchestrator on-premises deployments: versions 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1. Hosted and Dedicated VCO deployments already patched. VeloCloud Gateway and Edge products not affected.
Exploitation Status
Active exploitation confirmed by Arista and CISA. Three attacker IP addresses identified: 8.19.75.217, 206.72.242.124, 206.72.242.162. Exploitation details and threat actor identity not disclosed.
Business Impact
CVSS 10.0 unauthenticated OS command injection allows remote attackers to compromise orchestrator confidentiality, integrity, and availability without credentials. Only network access to VCO web interface required. Successful exploitation can compromise managed SD-WAN infrastructure including VeloCloud Edge devices, credentials, certificates, and configuration data. VCO is exposed by default with no configuration option to prevent exposure. CISA BOD 22-01 mandates federal agency remediation by July 30, 2026.
Urgency
🔴 Immediate
Recommended Actions
- Immediately upgrade on-premises VeloCloud Orchestrator to patched versions: 5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1 and later
- Block attacker IPs (8.19.75.217, 206.72.242.124, 206.72.242.162) at perimeter firewalls and search VCO logs for connections from these addresses
- Restrict VCO web interface access to administrative networks only via firewall rules or network segmentation until patching is complete
- Review VCO logs for indicators of compromise: unusual web requests with encoded characters, unexpected outbound HTTP/HTTPS traffic, unauthorized configuration changes, unexpected command execution or file creation, and suspicious database access
- If compromise is suspected, preserve logs and filesystem timestamps, rotate all VCO credentials and certificates, validate managed Edge device integrity, and consider full orchestrator replacement rather than in-place patching
