Executive brief
VeloCloud Edge is network edge software used to manage and secure branch office connectivity to cloud applications and corporate networks. A vulnerability in its software update workflow allows attackers with administrator privileges or direct Edge access to bypass signature validation and install unauthorized software, potentially compromising network security and enabling malware deployment.
Technical details
The VeloCloud Edge software update workflow fails to properly validate cryptographic signatures on update bundles because it does not restrict the digest algorithm used for artifact verification (CWE-347: Improper Verification of Cryptographic Signature). An attacker requires either high-privilege access to VeloCloud Orchestrator to upload malicious packages, or direct credentials to access an Edge device. The attack vector is network-based but requires high privileges (PR:H) and high complexity (AC:H). Successful exploitation allows installation of arbitrary software on Edge devices, compromising confidentiality, integrity, and availability. Patches are available in VeloCloud Edge 5.2.7.0+, 6.1.5.0+, 6.4.2+, and 7.0.0+. No hotfix is available for older versions.
Affected products
- Arista VeloCloud Edge 6.4.1.x and below in 6.4.x train; 6.1.4.x and below in 6.1.x train; 5.2.6.x and below in 5.2.x train; all prior releases
Timeline
- 2026-09-09: disclosed: Arista Security Advisory 0182 initial release
- 2026-09-22: advisory: CSAF JSON file added to advisory