8.3

CVE-2023-34063

Aria Automation contains a Missing Access Control vulnerability.


An authenticated malicious actor may 
exploit this vulnerability leading to unauthorized access to remote 
organizations and workflows.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Aria Automation Version 8.11.0
VMware ≫ Aria Automation Version 8.11.1
VMware ≫ Aria Automation Version 8.11.2
VMware ≫ Aria Automation Version 8.12.0
VMware ≫ Aria Automation Version 8.12.1
VMware ≫ Aria Automation Version 8.12.2
VMware ≫ Aria Automation Version 8.13.0
VMware ≫ Aria Automation Version 8.13.1
VMware ≫ Aria Automation Version 8.14.0
VMware ≫ Aria Automation Version 8.14.1
VMware ≫ Cloud Foundation Version 4.0
VMware ≫ Cloud Foundation Version 5.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.95% 0.565
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.3 2.8 5.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
VMware 9.9 3.1 6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://www.vmware.com/security/advisories/VMSA-2024-0001.html
Patch
Vendor Advisory