peter bassill · operator
$ cve CVE-2023-34051 JSON

CVE-2023-34051

9.8
CRITICAL · CVSS 3.1 · EPSS 44.7% (pctl 99)

Patch early

EPSS 44.7% — above the 10% action threshold.

Description

VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS44.67% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-863
On CISA KEVno
Public exploitnone known
Published2023-10-20
Last modified2026-06-17

Affected (1)

VendorProduct
vmwarearia operations for logs

References

→ the Explorer  ·  watch your stack  ·  NVD