HomeCyber BalkansVMware Aria Operations Networks at Risk from Remote Attacks

VMware Aria Operations Networks at Risk from Remote Attacks

Published on

spot_img


Critical Vulnerability

VMware has released software updates to correct two security vulnerabilities in Aria Operations for Networks that could be potentially exploited to bypass authentication and gain remote code execution.

The most severe of the flaws is CVE-2023-34039 (CVSS score: 9.8), which relates to a case of authentication bypass arising as a result of a lack of unique cryptographic key generation.

“A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to gain access to the Aria Operations for Networks CLI,” the company said in an advisory.

ProjectDiscovery researchers Harsh Jaiswal and Rahul Maini have been credited with discovering and reporting the issue.

The second weakness, CVE-2023-20890 (CVSS score: 7.2), is an arbitrary file write vulnerability impacting Aria Operations for Networks that could be abused by an adversary with administrative access to write files to arbitrary locations and achieve remote code execution.

Credited with reporting the bug is Sina Kheirkhah of Summoning Team, who previously uncovered multiple flaws in the same product, including CVE-2023-20887, which came under active exploitation in the wild in June 2023.

The vulnerabilities, which affect VMware Aria Operations Networks versions 6.2, 6.3, 6.4, 6.5.1, 6.6, 6.7, 6.8, 6.9, and 6.10, have been addressed in a series of patches released by VMware for each of the versions.

The virtualization services provider said that version 6.11.0 comes with fixes for the two flaws.

Given that security issues in VMware are a lucrative target for threat actors in the past, it’s imperative that users move quickly to update to the latest version to safeguard against potential threats.

-REFERENCE: https://thehackernews.com/2023/08/critical-vulnerability-alert-vmware.html

-K.Z



Source link

Latest articles

The Data-First Strategy for CMMC

Why Organizations Should Identify CUI Before Mapping Controls In navigating the complexities of Cybersecurity Maturity...

Cisco Talos Alerts on AI Agent Swarms Potential to Accelerate Cyberattacks from Months to Hours

Cisco Talos Warns of AI Agent Swarms: A New Era in Cybersecurity Threats Cisco Talos...

Proofpoint Focuses on Intent-Based Detection

Emerging Threats Demand Innovative Solutions: Proofpoint's Response at Protect26 Conference Amidst a concerning rise in...

Major AI Firms Commit to Data Protection Reforms After ICO Initiative

On October 8, the Information Commissioner's Office (ICO), the British authority responsible for upholding...

More like this

The Data-First Strategy for CMMC

Why Organizations Should Identify CUI Before Mapping Controls In navigating the complexities of Cybersecurity Maturity...

Cisco Talos Alerts on AI Agent Swarms Potential to Accelerate Cyberattacks from Months to Hours

Cisco Talos Warns of AI Agent Swarms: A New Era in Cybersecurity Threats Cisco Talos...

Proofpoint Focuses on Intent-Based Detection

Emerging Threats Demand Innovative Solutions: Proofpoint's Response at Protect26 Conference Amidst a concerning rise in...