9.8
CVE-2023-20864
- EPSS 92.75%
- Veröffentlicht 20.04.2023 21:15:08
- Zuletzt bearbeitet 05.02.2025 16:15:34
- Quelle security@vmware.com
- Teams Watchlist Login
- Unerledigt Login
VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Aria Operations For Logs Version >= 8.10.2 < 8.12.0
VMware ≫ Cloud Foundation Version >= 4.0 <= 4.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 92.75% | 0.997 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.