Arista patches actively exploited VeloCloud bug with perfect 10 severity
UKPulse News Desk
Arista has issued a patch for an actively exploited VeloCloud vulnerability that scores a perfect 10 on the CVSS scale. The bug allows unauthenticated command injection and may expose managed Edge devices.
- The vulnerability is an unauthenticated command injection flaw with a CVSS score of 10.
- It is being actively exploited and may expose managed Edge devices.
- CISA has put administrators on a deadline to apply the patch.
Arista has released a patch for a VeloCloud vulnerability that is being actively exploited. The flaw, which scores a perfect 10 on the CVSS severity scale, allows unauthenticated command injection and may expose managed Edge devices.
The US Cybersecurity and Infrastructure Security Agency (CISA) has given administrators a deadline to apply the fix.
Why this matters: The vulnerability is already being exploited in the wild and carries the highest possible severity rating, putting affected systems at immediate risk.
What this means for you: If you manage Arista VeloCloud Edge devices, you should apply the patch immediately to prevent potential compromise.