VYPR

Velocloud Orchestrator

by Arista

CVEs (4)

  • CVE-2026-31431HigKEVApr 22, 2026
    risk 0.67cvss 7.8epss 1.00

    In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the…

  • CVE-2020-3973HigJul 8, 2020
    risk 0.57cvss 8.8epss 0.01

    The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection. A malicious actor with tenant access to Velocloud Orchestrator could enter specially crafted SQL queries and obtain data to which they are not privileged.

  • CVE-2026-16812CriKEVJul 27, 2026
    risk 0.12cvss 10.0epss 0.02

    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator…

  • CVE-2026-17191CriJul 27, 2026
    risk 0.00cvss 9.1epss 0.03

    An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend queries, which may result in unauthorized access to data beyond their intended privileges and cause the underlying system to…