CVE-2023-34051

EUVD-2023-38168
VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
Affected Products (NVD)
VendorProductVersion
vmwarearia_operations_for_logs
4.0
vmwarearia_operations_for_logs
5.0
vmwarearia_operations_for_logs
8.6
vmwarearia_operations_for_logs
8.8
vmwarearia_operations_for_logs
8.10
vmwarearia_operations_for_logs
8.10.2
vmwarearia_operations_for_logs
8.12
𝑥
= Vulnerable software versions