CVE-2023-34039
Key Information
- Vendor
- Vmware
- Status
- Aria Operations for Networks
- Vendor
- CVE Published:
- 29 August 2023
Badges
Summary
Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to gain access to the Aria Operations for Networks CLI.
Affected Version(s)
Aria Operations for Networks = Aria Operations for Networks 6.x
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
PoC exploit code released for CVE-2023-34039 bug in VMware Aria Operations for Networks
Researcher released PoC exploit code for a recent critical flaw (CVE-2023-34039) in VMware Aria Operations for Networks.
1 year ago
VMware fixes critical vulnerability in Aria Operations for Networks (CVE-2023-34039) - Help Net Security
VMware has patched one critical (CVE-2023-34039) and one high-severity vulnerability (CVE-2023-20890) in its Aria Operations for Networks.
1 year ago
EPSS Score
94% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 👾
Exploit exists.
First article discovered by Help Net Security
Vulnerability published.
Vulnerability Reserved.