Vulnerability Description
Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to gain access to the Aria Operations for Networks CLI.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Aria Operations For Networks | >= 6.2.0, < 6.11.0 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/174452/VMWare-Aria-Operations-For-Networks-Third Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/175320/VMWare-Aria-Operations-For-Networks-ExploitThird Party AdvisoryVDB Entry
- https://www.vmware.com/security/advisories/VMSA-2023-0018.htmlPatchVendor Advisory
- http://packetstormsecurity.com/files/174452/VMWare-Aria-Operations-For-Networks-Third Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/175320/VMWare-Aria-Operations-For-Networks-ExploitThird Party AdvisoryVDB Entry
- https://www.vmware.com/security/advisories/VMSA-2023-0018.htmlPatchVendor Advisory
FAQ
What is CVE-2023-34039?
CVE-2023-34039 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Operations for Networks...
How severe is CVE-2023-34039?
CVE-2023-34039 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-34039?
Check the references section above for vendor advisories and patch information. Affected products include: Vmware Aria Operations For Networks.