CVE-2023-34039: Critical severity vmware vrealize operations vulnerability
Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to gain access to the Aria Operations for Networks CLI.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-34039?
CVE-2023-34039 is an Authentication Bypass vulnerability in Aria Operations for Networks due to a lack of unique cryptographic key generation.
How does CVE-2023-34039 affect VMware Aria Operations for Networks?
CVE-2023-34039 affects VMware Aria Operations for Networks version 6.2.0 to 6.11.0.
What is the severity of CVE-2023-34039?
CVE-2023-34039 has a severity rating of critical with a CVSS score of 9.8.
How can an attacker exploit CVE-2023-34039?
An attacker with network access can exploit CVE-2023-34039 to bypass SSH authentication and gain access to the Aria Operations for Networks command-line interface (CLI).
Are there any known fixes for CVE-2023-34039?
Yes, VMware has released a security advisory (VMSA-2023-0018) containing the necessary patches to address the Authentication Bypass vulnerability in Aria Operations for Networks.