VulnerabilityModified
CVE-2023-34051
VMware Aria Operations for Logs contains an authentication bypass vulnerability.
CRITICAL 9.8EPSS 44.7%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 44.7%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 44.67% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- vmware/aria operations for logs
- Source
- security@vmware.com
References
- https://www.vmware.com/security/advisories/VMSA-2023-0021.htmlPatch, Vendor Advisory
- https://www.vmware.com/security/advisories/VMSA-2023-0021.htmlPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.