ZeroHour

CVE-2023-34039

PoC
CVSS 3.1
9.8 critical
EPSS
67%p99
Published
()
Modified
Description

Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to gain access to the Aria Operations for Networks CLI.

Vendors
vmware
Products
aria operations for networks
Weakness
CWE-327
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news