9.8
CVE-2023-34051
- EPSS 44.67%
- Veröffentlicht 20.10.2023 05:15:07
- Zuletzt bearbeitet 02.05.2025 19:15:55
- Erkennungen
VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Aria Operations For Logs Version 4.0
VMware ≫ Aria Operations For Logs Version 5.0
VMware ≫ Aria Operations For Logs Version 8.6
VMware ≫ Aria Operations For Logs Version 8.8
VMware ≫ Aria Operations For Logs Version 8.10
VMware ≫ Aria Operations For Logs Version 8.10.2
VMware ≫ Aria Operations For Logs Version 8.12
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 44.67% | 0.986 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| CISA-ADP | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
https://www.vmware.com/security/advisories/VMSA-2023-0021.html