Known vulnerabilities in VeloCloud Orchestrator (VCO)
Vendor:
Arista Networks
Software:
VeloCloud Orchestrator (VCO)
Software CPE:
cpe:2.3:a:arista:velocloud_orchestrator_vco:*:*:*:*:*:*:*:*
Website:
https://www.arista.com/en/
Total vulnerabilities:
3
Public exploits:
0
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU140095 - Server-Side Request Forgery (SSRF) CVE-2026-17192 |
CWE-918 | Medium | 5.2.3.14, 6.1.3.4, 6.4.2.4 | 30.07.2026 |
SB2026073026 |
||
| #VU140092 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2026-17191 |
CWE-89 | Medium | 5.2.3.14, 6.1.3.4, 6.4.2.4 | 30.07.2026 |
SB2026073026 |
||
| #VU140091 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2026-16812 |
CWE-78 | High | 5.2.3.14, 6.1.3.4, 6.4.2.4, 7.0.0.1 | 30.07.2026 |
SB2026073026 |