ZDI-CAN-20380: ZDI-23-482: VMware Aria Operations for Logs Cluster Controller Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published Apr 24, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VMware Aria Operations for Logs. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
VMware Aria Operations for Logs
Event History
Apr 24, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-20380?
The severity of ZDI-CAN-20380 is rated at 89, indicating a high risk.
2
How do I fix ZDI-CAN-20380?
To fix ZDI-CAN-20380, apply the latest security patches provided by VMware for Aria Operations for Logs.
3
What software is affected by ZDI-CAN-20380?
ZDI-CAN-20380 affects VMware Aria Operations for Logs installations.
4
Is authentication required to exploit ZDI-CAN-20380?
No, authentication is not required to exploit ZDI-CAN-20380, making it particularly dangerous.
5
What type of vulnerability is ZDI-CAN-20380?
ZDI-CAN-20380 is a deserialization of untrusted data vulnerability that leads to remote code execution.