CVE-2024-22240: Medium severity VMware Aria Operations for Networks vulnerability
Published Feb 6, 2024
·Updated
Aria Operations for Networks contains a local file read vulnerability. A malicious actor with admin privileges may exploit this vulnerability leading to unauthorized access to sensitive information.
Affected Software
1 affected component
VMware Aria Operations for Networks>=6.0.0<=6.12.0
Event History
Feb 6, 2024
CVE Published
via MITRE·07:39 PM
Data Sourced
via MITRE·07:39 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-22240?
CVE-2024-22240 has a high severity due to its potential for unauthorized access to sensitive information.
2
How do I fix CVE-2024-22240?
To fix CVE-2024-22240, upgrade the VMware Aria Operations for Networks to a version beyond 6.12.0.
3
Who is affected by CVE-2024-22240?
CVE-2024-22240 affects VMware Aria Operations for Networks versions between 6.0.0 and 6.12.0.
4
What type of vulnerability is CVE-2024-22240?
CVE-2024-22240 is classified as a local file read vulnerability.
5
Can CVE-2024-22240 be exploited remotely?
CVE-2024-22240 requires a malicious actor to have admin privileges, therefore it cannot be exploited remotely.