9.8
CVE-2023-34051
- EPSS 57.74%
- Published 20.10.2023 05:15:07
- Last modified 02.05.2025 19:15:55
- Source security@vmware.com
- Teams watchlist Login
- Open Login
VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.
Data is provided by the National Vulnerability Database (NVD)
VMware ≫ Aria Operations For Logs Version4.0
VMware ≫ Aria Operations For Logs Version5.0
VMware ≫ Aria Operations For Logs Version8.6
VMware ≫ Aria Operations For Logs Version8.8
VMware ≫ Aria Operations For Logs Version8.10
VMware ≫ Aria Operations For Logs Version8.10.2
VMware ≫ Aria Operations For Logs Version8.12
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 57.74% | 0.981 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.