CVE Vulnerabilities

CVE-2023-34043

Improper Privilege Management

Published: Sep 27, 2023 | Modified: Sep 29, 2023
CVSS 3.x
6.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to root.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Aria_operations Vmware 8.6.0 (including) 8.6.0 (including)
Aria_operations Vmware 8.10.0 (including) 8.10.0 (including)
Aria_operations Vmware 8.12.0 (including) 8.12.0 (including)
Aria_operations Vmware 8.12.0-hotfix1 (including) 8.12.0-hotfix1 (including)
Aria_operations Vmware 8.12.0-hotfix2 (including) 8.12.0-hotfix2 (including)
Aria_operations Vmware 8.12.0-hotfix3 (including) 8.12.0-hotfix3 (including)
Cloud_foundation Vmware 4.0 (including) 4.4 (excluding)
Cloud_foundation Vmware 5.0 (including) 5.0 (including)

Potential Mitigations

References