VYPR
High severity8.8NVD Advisory· Published Jul 8, 2020· Updated Jul 28, 2026

CVE-2020-3973

CVE-2020-3973

Description

The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection. A malicious actor with tenant access to Velocloud Orchestrator could enter specially crafted SQL queries and obtain data to which they are not privileged.

Affected products

5
  • cpe:2.3:a:arista:velocloud_orchestrator:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:arista:velocloud_orchestrator:*:*:*:*:*:*:*:*range: >=3.1.1,<3.3.2
    • cpe:2.3:a:arista:velocloud_orchestrator:3.3.2:-:*:*:*:*:*:*
    • cpe:2.3:a:arista:velocloud_orchestrator:3.4.0:*:*:*:*:*:*:*
  • VeloCloud/VeloCloud Orchestratordescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.