CVE-2023-34051
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/10/2023
Last modified:
02/05/2025
Description
VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.<br />
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:vmware:aria_operations_for_logs:4.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:aria_operations_for_logs:5.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:aria_operations_for_logs:8.6:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:aria_operations_for_logs:8.8:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:aria_operations_for_logs:8.10:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:aria_operations_for_logs:8.10.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:aria_operations_for_logs:8.12:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page