Executive brief
Arista VeloCloud Orchestrator, a platform used to manage SD-WAN networks, contains a security flaw in its flow metrics API. An authenticated user with even low-level access can manipulate database queries to view sensitive information they are not authorized to see. Additionally, this flaw can be used to force the orchestrator to make unauthorized connections to other internal systems, potentially leading to further network compromise.
Technical details
An SQL injection vulnerability (CWE-89) exists in the flow metrics API component of Arista VeloCloud Orchestrator (VCO). The flaw is caused by improper neutralization of special elements in user-supplied input, allowing an authenticated attacker to manipulate backend SQL queries. Successful exploitation enables unauthorized data access and Server-Side Request Forgery (SSRF), where the system can be forced to initiate outbound network connections. The attack requires a valid session with at least 'Enterprise Read Only' privileges. The issue is resolved in versions 5.2.3.14, 6.1.3.4, and 6.4.2.4.
Affected products
- Arista Networks VeloCloud Orchestrator On-Prem 5.2.x prior to 5.2.3.14, 6.1.x prior to 6.1.3.4, 6.4.x prior to 6.4.2.4
Timeline
- 2026-07-27: advisory
- 2026-07-27: patched