#Arista
All CosmicBytez Labs articles tagged #Arista, across news, security advisories, how-to guides, and projects.
- News
Arista Urges Immediate Patching of Exploited VCO Zero-Day
Arista's VeloCloud Orchestrator has a critical zero-day (CVE-2026-93952, CVSS 10.0) under active attack; patch now or restrict web-interface access.
- News
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
Arista disclosed CVE-2026-93952, a CVSS 10.0 pre-auth privilege escalation in VeloCloud Orchestrator, already under active exploitation.
- News
Arista Patches VeloCloud Orchestrator Zero-Day Exploited in Attacks
Arista Networks has released an emergency patch for a maximum-severity command injection zero-day in on-premises VeloCloud Orchestrator deployments that...
- Security
CVE-2024-27890: Arista EOS OpenConfig gNMI Authorization Bypass (CVSS 9.6)
Arista EOS platforms with OpenConfig configured are vulnerable to unauthorized gNMI Set requests that should have been rejected, allowing attackers to apply…
- Security
CVE-2024-27892: Arista EOS OpenConfig gNMI Set Bypass (CVSS 9.6)
A second critical OpenConfig authorization bypass in Arista EOS allows gNMI Set requests that should be rejected to execute, enabling unauthorized network…