CVE-2026-86109
6.6
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Summary
The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures because the workflow does not restrict the digest algorithm used for artifact verification. An attacker with either sufficient privileges to upload packages to VeloCloud Orchestrator or credentials permitting direct access to an Edge may be able to install unauthorized software.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Arista Networks | VeloCloud Edge | 6.4.0 <= 6.4.1.x | affected |
| Arista Networks | VeloCloud Edge | 6.1.0 <= 6.1.4.x | affected |
| Arista Networks | VeloCloud Edge | 5.2.0 <= 5.2.6.x | affected |
| Arista Networks | VeloCloud Edge | 0.0.0 < 5.2.0 | affected |
Weaknesses
- CWE-347: CWE-347: Improper Verification of Cryptographic Signature
Workarounds
- Restrict software-image management and VeloCloud Edge update privileges to trusted administrators.
- Protect VeloCloud Orchestrator administrative credentials and management access.
- Obtain and distribute VeloCloud Edge software only through trusted Arista management and distribution channels.
- Investigate unexpected software images or update operations before permitting installation. These measures reduce exposure but do not correct the vulnerable update-verification workflow.
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.