Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-34051


VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.


Published

2023-10-20T05:15:07.943

Last Modified

2025-05-02T19:15:55.293

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-863
  • Type: Secondary
    CWE-863

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application vmware aria_operations_for_logs 4.0 Yes
Application vmware aria_operations_for_logs 5.0 Yes
Application vmware aria_operations_for_logs 8.6 Yes
Application vmware aria_operations_for_logs 8.8 Yes
Application vmware aria_operations_for_logs 8.10 Yes
Application vmware aria_operations_for_logs 8.10.2 Yes
Application vmware aria_operations_for_logs 8.12 Yes

References