CVE-2020-3973: Arista VeloCloud Orchestrator

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection. A malicious actor with tenant access to Velocloud Orchestrator could enter specially crafted SQL queries and obtain data to which they are not privileged.

Affected products

  • Arista VeloCloud Orchestrator: from 3.1.1, before 3.3.2 (fixed in 3.3.2); version 3.3.2 only; version 3.4.0 only

Published 2020-07-08. Last modified 2026-07-28.