An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions without verification. This could result in elevated command execution on Edge units where HA is enabled.
The vulnerability requires HA to be enabled and the attacker to have Layer 2 network access to the dedicated HA interconnect.
Use dedicated port-to-port connections between HA pairs. Avoid extending the HA interconnect through shared switches or VLANs. Restrict physical and network access to HA interfaces.
The following VeloCloud Edge releases contain the fix:
- 5.2.7.0 and later in the 5.2.x train
- 6.1.5.0 and later in the 6.1.x train
- 6.4.2 and later in the 6.4.x train
- 7.0.0 and later
No hotfixes are available for this issue.