Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may allow an authorized management request or configuration value to be interpreted as an operating-system command. Successful exploitation may allow command execution with elevated privileges on the affected VeloCloud Edge.
Credits
This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.