CVE-2023-34039 is a critical Authentication Bypass vulnerability in VMware Aria Operations for Networks, stemming from a lack of unique cryptographic key generation. This flaw allows an unauthenticated attacker with network access to bypass SSH authentication and gain full access to the CLI. With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating high exploitability, this vulnerability poses a severe risk, enabling complete compromise of confidentiality, integrity, and availability. Exploit code, including a Metasploit module, has been publicly released, and the vulnerability has garnered significant community attention and media coverage, indicating a high likelihood of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.2.0, < 6.11.0CPE matchmatch criteria | cpe:2.3:a:vmware:aria_operations_for_networks:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.