CVE-2023-34052

VMware Aria Operations for Logs contains a deserialization vulnerability.A malicious actor with non-administrative access to the local system can trigger the deserialization of data which could result in authentication bypass.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vmwareCNA
---
---
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 5%
VendorProductVersion
vmwarearia_operations_for_logs
4.0
vmwarearia_operations_for_logs
5.0
vmwarearia_operations_for_logs
8.10.2
vmwarearia_operations_for_logs
8.12
𝑥
= Vulnerable software versions