CVE-2024-22241
- EPSS 3.55%
- Veröffentlicht 06.02.2024 20:16:04
- Zuletzt bearbeitet 03.06.2025 19:15:37
Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges can inject a malicious payload into the login banner and takeover the user account.
CVE-2024-22237
- EPSS 0.12%
- Veröffentlicht 06.02.2024 20:16:03
- Zuletzt bearbeitet 15.05.2025 20:15:42
Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may exploit this vulnerability to escalate privileges to gain root access to the system.
CVE-2024-22238
- EPSS 1.67%
- Veröffentlicht 06.02.2024 20:16:03
- Zuletzt bearbeitet 03.06.2025 19:15:37
Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges may be able to inject malicious code into user profile configurations due to improper input sanitization.
CVE-2024-22239
- EPSS 0.07%
- Veröffentlicht 06.02.2024 20:16:03
- Zuletzt bearbeitet 15.05.2025 20:15:42
Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may exploit this vulnerability to escalate privileges to gain regular shell access.
CVE-2024-22240
- EPSS 0.54%
- Veröffentlicht 06.02.2024 20:16:03
- Zuletzt bearbeitet 15.05.2025 20:15:43
Aria Operations for Networks contains a local file read vulnerability. A malicious actor with admin privileges may exploit this vulnerability leading to unauthorized access to sensitive information.
CVE-2023-20890
- EPSS 0.79%
- Veröffentlicht 29.08.2023 18:15:08
- Zuletzt bearbeitet 21.11.2024 07:41:45
Aria Operations for Networks contains an arbitrary file write vulnerability. An authenticated malicious actor with administrative access to VMware Aria Operations for Networks can write files to arbitrary locations resulting in remote code execution.
CVE-2023-34039
- EPSS 93.25%
- Veröffentlicht 29.08.2023 18:15:08
- Zuletzt bearbeitet 21.11.2024 08:06:27
Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to gain access to...
CVE-2023-20887
- EPSS 94.39%
- Veröffentlicht 07.06.2023 15:15:09
- Zuletzt bearbeitet 12.02.2025 20:10:18
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution.