← All CVEs

CVE-2023-34051

critical · 9.8

VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.

9.8
CVSS
44.7%
EPSS (exploit prob.)
99th
EPSS percentile
2023-10-20
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-863

Affected products

VendorProductAffected versions
vmwarearia_operations_for_logs4.0
vmwarearia_operations_for_logs5.0
vmwarearia_operations_for_logs8.6
vmwarearia_operations_for_logs8.8
vmwarearia_operations_for_logs8.10
vmwarearia_operations_for_logs8.10.2
vmwarearia_operations_for_logs8.12

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-34051