CVE-2023-34039
Severity CVSS v4.0:
Pending analysis
Type:
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
Publication date:
29/08/2023
Last modified:
09/01/2024
Description
Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to gain access to the Aria Operations for Networks CLI.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:vmware:aria_operations_for_networks:*:*:*:*:*:*:*:* | 6.2.0 (including) | 6.11.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



