CVE-2023-34039

Severity CVSS v4.0:
Pending analysis
Type:
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
Publication date:
29/08/2023
Last modified:
09/01/2024

Description

Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to gain access to the Aria Operations for Networks CLI.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:aria_operations_for_networks:*:*:*:*:*:*:*:* 6.2.0 (including) 6.11.0 (excluding)