CVE-2023-34039: VMware Aria Operations for Networks
Critical severity, CVSS 9.8. EPSS: 67.2% chance of exploitation in the next 30 days.
Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to gain access to the Aria Operations for Networks CLI.
Affected products
- VMware Aria Operations for Networks: from 6.2.0, before 6.11.0 (fixed in 6.11.0)
Published 2023-08-29. Last modified 2026-06-17.