SeguridadNo verificado

New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups

Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to authenticate their Edges with certificates are

Se muestra el contenido original; la traduccion localizada aun no esta disponible.

Qué ocurrió

Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to authenticate their Edges with certificates are

Por que importa

The incident may affect operational continuity, asset safety or trust around Security. Watch for verified scope and remediation.

Entidades afectadas

Ver evidencia

1 articulos · 1 informe original · 1 independientes

  1. The Hacker NewsFuente primaria · Respalda · EN · 100%
    New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups ↗

Afirmaciones

  • New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups Observado

Conflictos

No se detectaron conflictos importantes en la evidencia disponible.

Cronología

  1. Primera publicación

Movimiento del mercado posterior al evento

La reacción del mercado aún no está disponible para este activo y periodo.

Explicación de puntuaciones

Confianza · fórmula confidence-2.1.0
Fiabilidad de fuentes80
Corroboración independiente51
Evidencia primaria35
Coherencia de afirmaciones82
Confianza de extracción82
Calidad de atribución90
Impacto · fórmula impact-2.1.0
Magnitud del evento96
Relevancia de mercado74
Importancia de entidades42
Alcance del mercado45
Novedad68
Urgencia93
Clasificación · fórmula rank-1.0.0
Factor de confianza0.8425
Factor de actualidad0.988
Bono de urgencia8
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups | IntelCap