Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-34063


Aria Automation contains a Missing Access Control vulnerability. An authenticated malicious actor may exploit this vulnerability leading to unauthorized access to remote organizations and workflows.


Published

2024-01-16T10:15:07.347

Last Modified

2025-06-20T17:15:30.883

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.9 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-862
  • Type: Secondary
    CWE-862

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application vmware aria_automation 8.11.0 Yes
Application vmware aria_automation 8.11.1 Yes
Application vmware aria_automation 8.11.2 Yes
Application vmware aria_automation 8.12.0 Yes
Application vmware aria_automation 8.12.1 Yes
Application vmware aria_automation 8.12.2 Yes
Application vmware aria_automation 8.13.0 Yes
Application vmware aria_automation 8.13.1 Yes
Application vmware aria_automation 8.14.0 Yes
Application vmware aria_automation 8.14.1 Yes
Application vmware cloud_foundation 4.0 Yes
Application vmware cloud_foundation 5.0 Yes

References