{
  "document": {
    "category": "security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "publisher": {
      "category": "vendor",
      "contact_details": "support@arista.com",
      "name": "Arista PSIRT",
      "namespace": "https://www.arista.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Security advisory 179 canonical URL",
        "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24735-security-advisory-0179"
      }
    ],
    "title": "Security Advisory 179",
    "tracking": {
      "current_release_date": "2026-09-17T11:48:24Z",
      "generator": {
        "engine": {
          "name": "Arista Networks SecEng Service CSAF Generator"
        }
      },
      "id": "Arista Networks Security Advisory 179",
      "initial_release_date": "2026-09-17T11:48:24Z",
      "revision_history": [
        {
          "date": "2026-09-17T11:48:24Z",
          "number": "1",
          "summary": "Document created"
        }
      ],
      "status": "draft",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "SD-WAN version 1.0.0",
                    "product": {
                      "name": "SD-WAN version 1.0.0",
                      "product_id": "CSAFPID-0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "SD-WAN"
              }
            ],
            "category": "product_family",
            "name": "Software Products"
          }
        ],
        "category": "vendor",
        "name": "Arista Networks, Inc."
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-86106",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1833882"
      },
      "notes": [
        {
          "category": "description",
          "text": "On a VeloCloud Edge, an unauthenticated actor with network access to the private HA (High Availability) interconnect may trigger sensitive HA peer functions without verification. This could result in elevated command execution on Edge units where HA is enabled. ",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "Exploitation requires HA to be enabled and the attacker to have Layer 2 network access to the dedicated HA interconnect. In the VeloCloud Orchestrator, select the VeloCloud Edge and review its Device > High Availability configuration to determine whether Active/Standby HA is enabled. The standard direct port-to-port HA connection limits access; extending the HA connection through a shared switch or VLAN increases exposure.\n\n![kix.hoo45myrhr20](https://lh7-rt.googleusercontent.com/docsz/AD_4nXfHbbGCT68WZpd1rdz8tjUwP2ugB8PcymVK0mawuuOgH9XN7NCzWi5iQ5a-PkjdiX29_wxMlAI2vdPBPz4dHtA336ZH-19SY0xFNw8hQYvjNDDLECHg8Teh4Vc-VOKDwVxxh3ERd2HoXsbQaBCFneZU7pFQs3xD_ikQIkO-0lA4zvsAK6w=s2048?key=Chsy3cykDUBeVH91pvnJ5g)",
          "title": "1833882: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-0"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-86106"
        }
      ],
      "remediations": [
        {
          "category": "none_available",
          "details": "Not fixed in SD-WAN version 1.0.0",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "mitigation",
          "details": "Until an upgrade can be completed, customers should:\n\n* Use the recommended direct, dedicated port-to-port connection between the HA pair.\n* Do not extend the HA interconnect through a shared or user-accessible switch or VLAN.\n* Restrict physical and network access to the HA interfaces."
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.6,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-0"
          ]
        }
      ],
      "title": "CVE-2026-86106"
    }
  ]
}