CVE-2023-34051
9.8
CRITICAL · CVSS 3.1 · EPSS 44.7% (pctl 99)
Patch early
EPSS 44.7% — above the 10% action threshold.
Description
VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 44.67% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-863 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2023-10-20 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| vmware | aria operations for logs |
References
→ the Explorer · watch your stack · NVD