By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Arista Patches Actively Exploited VeloCloud Orchestrator Zero-Day
Arista Networks has issued security patches to address a critical zero-day vulnerability affecting VeloCloud Orchestrator (VCO) On-Prem deployments. This flaw was confirmed to be under active exploitation, meaning malicious actors were already leveraging it to compromise systems before a fix was available. The vulnerability, identified as CVE-2024-21778, allows an unauthenticated, remote attacker to execute arbitrary code on the affected appliance. The exploitation of this vulnerability could lead to a complete compromise of the targeted system, enabling attackers to gain unauthorized access, steal sensitive data, or disrupt operations.
VeloCloud Orchestrator is a key component within VMware's SD-WAN solution, which Arista Networks acquired through its acquisition of the company. VCO is designed to manage and orchestrate network services for distributed enterprise environments, providing centralized control over virtual network functions and connectivity. Its role in managing critical network infrastructure makes vulnerabilities within it particularly concerning. The active exploitation of CVE-2024-21778 highlights the immediate threat posed by unpatched systems, underscoring the importance of timely security updates for network management platforms.
Arista Networks has provided specific guidance for customers to mitigate the risk associated with this vulnerability. The recommended actions include updating the VeloCloud Orchestrator software to the patched versions as soon as possible. The company has not disclosed the exact number of systems affected or the specific nature of the exploits observed in the wild, citing ongoing investigations and security best practices. However, the classification of the vulnerability as a zero-day and its active exploitation indicate a high-priority threat that requires immediate attention from all users of the affected VeloCloud Orchestrator versions.
This incident serves as a stark reminder of the persistent threats faced by organizations relying on complex network infrastructure. The rapid exploitation of zero-day vulnerabilities underscores the need for robust security postures, including continuous monitoring, rapid patching, and comprehensive incident response plans. Arista Networks' swift response in releasing patches demonstrates their commitment to customer security, but the onus remains on users to implement these fixes promptly to protect their networks from further compromise. The specific versions of VeloCloud Orchestrator affected by CVE-2024-21778 are detailed in Arista's security advisory, urging administrators to consult it for precise identification and remediation steps.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.