CVE-2023-34039: VMware Aria Operations for Networks

Critical severity, CVSS 9.8. EPSS: 67.2% chance of exploitation in the next 30 days.

Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to gain access to the Aria Operations for Networks CLI.

Affected products

  • VMware Aria Operations for Networks: from 6.2.0, before 6.11.0 (fixed in 6.11.0)

Published 2023-08-29. Last modified 2026-06-17.