High severity8.8NVD Advisory· Published Jul 8, 2020· Updated Jul 28, 2026
CVE-2020-3973
CVE-2020-3973
Description
The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection. A malicious actor with tenant access to Velocloud Orchestrator could enter specially crafted SQL queries and obtain data to which they are not privileged.
Affected products
5cpe:2.3:a:arista:velocloud_orchestrator:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:arista:velocloud_orchestrator:*:*:*:*:*:*:*:*range: >=3.1.1,<3.3.2
- cpe:2.3:a:arista:velocloud_orchestrator:3.3.2:-:*:*:*:*:*:*
- cpe:2.3:a:arista:velocloud_orchestrator:3.4.0:*:*:*:*:*:*:*
- VeloCloud/VeloCloud Orchestratordescription
Patches
Vulnerability mechanics
References
1- www.vmware.com/security/advisories/VMSA-2020-0016.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.