Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability. The vulnerability allows attackers to inject OS commands. This is an executive overview: Arista VeloCloud Orchestrator On-Prem is affected by an OS command injection vulnerability. The vulnerability class is OS command injection, which can lead to potential operational impact, including unauthorized command execution. The source con [truncated]
CVE-2016-9012 describes a high-severity authorization flaw in Arista CloudVision Portal (CVP). An authenticated remote user could reach internal configuration mechanisms through the management plane by making a request associated with /web/system/console/bundle. The vulnerability applies to CVP versions before 2016.1.2.1, with NVD listing affected CPE versions through 2016.1.2.0.