Skip to content
arrow-alt-circle-up icon

Cyber Incident?

arrow-alt-circle-up icon

Call 00800 1744 0000

arrow-alt-circle-up icon

See all Threat Responses

Dutch follows English

Arista has disclosed a critical security vulnerability [1] in VeloCloud Orchestrator (VCO) on-premises deployments that allows attackers to compromise the system without any authentication. This vulnerability is actively being exploited in the wild.

Description
VeloCloud Orchestrator (VCO) on-premises contains a severe security flaw (CVE-2026-16812) that exposes privileged internal functionality to remote attackers. This functionality was never intended to be accessible from outside the system. Attackers can exploit this weakness without needing any credentials or user interaction - they simply need network access to the VCO web interface. The vulnerability has been assigned the maximum severity score of 10.0 out of 10.0.

Impact
We estimate the impact of these vulnerabilities as HIGH. Successful exploitation allows attackers to compromise the VeloCloud Orchestrator system. This means attackers can access, modify, or delete any data managed by the orchestrator, including sensitive configuration information, credentials, certificates, and device inventories. The compromise may also extend to VeloCloud Edge devices managed by the affected orchestrator. Attackers have been observed using this vulnerability in active attacks.

Risk
We estimate the risk of these vulnerabilities as HIGH. The vulnerability is being actively exploited by attackers, and known malicious IP addresses have been identified conducting attacks. VCO systems are exposed by default with no configuration option to prevent exploitation. Any organisation running vulnerable VCO on-premises versions with the web interface accessible from untrusted networks faces immediate risk of compromise. The only requirement for exploitation is network connectivity to the VCO interface.

Mitigation
Arista has released fixed software versions that address this vulnerability:

  • VCO 5.2.3.14 or later (for 5.2 users)
  • VCO 6.1.3.4 or later (for 6.1 users)
  • VCO 6.4.2.4 or later (for 6.4 users)
  • VCO 7.0.0.1 or later (for 7.0 users)

Organisations should upgrade to these versions immediately. Note that hosted and dedicated VCO versions have already been patched.

What should you do?
If you use VeloCloud Orchestrator on-premises, you should take immediate action. First, upgrade to a fixed software version as soon as possible. Until you can upgrade, restrict access to the VCO web interface so only trusted administrative networks can reach it. Block the known malicious IP addresses identified by Arista (8.19.75.217, 206.72.242.124, 206.72.242.162). Review your VCO logs for signs of compromise, particularly looking for unusual web requests, unexpected outbound connections, or unauthorised configuration changes. If you suspect your system may have been compromised, preserve all logs before taking remediation action and consider rotating credentials and validating your managed device configurations.

What will Northwave do?
We will monitor any developments regarding this vulnerability. If new critical information about this threat arises we will reach out to you. You can contact us by phone or send us an email if you would like additional information.


E-mail: soc@northwave-cybersecurity.com
Do you have an incident right now? Call our Incident Response Team: 00800 1744 0000

Disclaimer applies, see below.

Sources

[1] https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144


Arista heeft een kritieke beveiligingskwetsbaarheid [1] bekendgemaakt in on-premises implementaties van VeloCloud Orchestrator (VCO) waarmee aanvallers het systeem kunnen compromitteren zonder enige authenticatie. Deze kwetsbaarheid wordt actief misbruikt in het wild.

Beschrijving
VeloCloud Orchestrator (VCO) on-premises bevat een ernstig beveiligingslek (CVE-2026-16812) dat interne functionaliteit blootstelt aan externe aanvallers. Deze functionaliteit was nooit bedoeld om van buiten het systeem toegankelijk te zijn. Aanvallers kunnen dit lek misbruiken zonder dat zij over inloggegevens beschikken — netwerktoegang tot de VCO-webinterface is voldoende. Aan de kwetsbaarheid is de maximale ernstgraad toegekend van 10,0 op 10,0.

Impact
Wij schatten de impact van deze kwetsbaarheden als HOOG. Succesvolle exploitatie stelt aanvallers in staat het VeloCloud Orchestrator-systeem te compromitteren. Dit betekent dat aanvallers alle door de orchestrator beheerde data kunnen inzien, wijzigen of verwijderen, waaronder gevoelige configuratie-informatie, inloggegevens, certificaten en apparaatinventarissen. De compromittering kan zich tevens uitstrekken tot VeloCloud Edge-apparaten die worden beheerd door de getroffen orchestrator. Aanvallers zijn waargenomen die deze kwetsbaarheid inzetten bij actieve aanvallen.

Risico
Wij schatten het risico van deze kwetsbaarheden als HOOG. De kwetsbaarheid wordt actief misbruikt door aanvallers en er zijn bekende kwaadaardige IP-adressen geïdentificeerd die aanvallen uitvoeren. VCO-systemen zijn standaard blootgesteld zonder configuratieoptie om exploitatie te voorkomen. Elke organisatie die kwetsbare VCO on-premises versies gebruikt met de webinterface bereikbaar vanuit niet-vertrouwde netwerken, loopt onmiddellijk risico op compromittering. De enige vereiste voor exploitatie is netwerkconnectiviteit naar de VCO-interface.

Mitigatie
Arista heeft gecorrigeerde softwareversies uitgebracht die deze kwetsbaarheid verhelpen:

  • VCO 5.2.3.14 of hoger (voor gebruikers van versie 5.2)
  • VCO 6.1.3.4 of hoger (voor gebruikers van versie 6.1)
  • VCO 6.4.2.4 of hoger (voor gebruikers van versie 6.4)
  • VCO 7.0.0.1 of hoger (voor gebruikers van versie 7.0)

Organisaties dienen onmiddellijk naar deze versies te upgraden. Hosted en dedicated VCO-versies zijn reeds gepatcht.

Wat dient u te doen?
Indien u VeloCloud Orchestrator on-premises gebruikt, dient u onmiddellijk actie te ondernemen. Upgrade zo spoedig mogelijk naar een nieuwere softwareversie. Totdat u kunt upgraden, beperk de toegang tot de VCO-webinterface zodat uitsluitend vertrouwde beheernetwerken deze kunnen bereiken. Blokkeer de door Arista geïdentificeerde bekende kwaadaardige IP-adressen (8.19.75.217, 206.72.242.124, 206.72.242.162). Controleer uw VCO-logs op indicaties van compromittering, met bijzondere aandacht voor ongebruikelijke webverzoeken, onverwachte uitgaande verbindingen of ongeautoriseerde configuratiewijzigingen. Indien u vermoedt dat uw systeem mogelijk is gecompromitteerd, bewaar dan alle logs vóórdat u herstelmaatregelen neemt en overweeg inloggegevens te roteren en de configuraties van uw beheerde apparaten te valideren.

Wat zal Northwave doen?
Wij zullen verdere ontwikkelingen met betrekking tot deze kwetsbaarheid monitoren. Indien er nieuwe kritieke informatie over deze dreiging beschikbaar komt, nemen wij contact met u op. U kunt ons telefonisch bereiken of een e-mail sturen voor aanvullende informatie.


E-mail: soc@northwave-cybersecurity.com
Heeft u op dit moment een incident? Bel ons Incident Response Team: 00800 1744 0000

Disclaimer van toepassing, zie onderaan.

Bronnen

[1] https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144

Disclaimer

Northwave has made every effort to make this information accurate and reliable. However, the information provided is without warranty of any kind and its use is at the sole risk of the user. Northwave does not accept any responsibility or liability for the accuracy, content, completeness, legality or reliability of the information provided. We will not be liable for any loss or damage of whatever nature, direct or indirect, consequential or other, whether arising in contract, tort or otherwise, which may arise as a result of your use of, or inability to use, this information or any additional information provided by us in direct or indirect relation to the information provided here.
.