CVE-2023-34063
published 2024-01-16CVE-2023-34063: Aria Automation contains a Missing Access Control vulnerability. An authenticated malicious actor may exploit this vulnerability leading to unauthorized access…
PriorityP349high8.3CVSS 3.1
AVNACLPRLUINSUCLIHAH
EPSS
0.95%
57.2th percentile
Aria Automation contains a Missing Access Control vulnerability.
An authenticated malicious actor may
exploit this vulnerability leading to unauthorized access to remote
organizations and workflows.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | aria_automation | — | — |
| vmware | aria_automation | — | — |
| vmware | aria_automation | — | — |
| vmware | aria_automation | — | — |
| vmware | aria_automation | — | — |
| vmware | aria_automation | — | — |
| vmware | aria_automation | — | — |
| vmware | aria_automation | — | — |
| vmware | aria_automation | — | — |
| vmware | aria_automation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fcww-v4hr-rgfr: Aria Automation contains a Missing Access Control vulnerability
ghsa_unreviewed·2024-01-16
CVE-2023-34063 [CRITICAL] CWE-862 GHSA-fcww-v4hr-rgfr: Aria Automation contains a Missing Access Control vulnerability
Aria Automation contains a Missing Access Control vulnerability.
An authenticated malicious actor may
exploit this vulnerability leading to unauthorized access to remote
organizations and workflows.
VMware
VMware Aria Automation (formerly vRealize Automation) updates address a Missing Access Control vulnerability (CVE-2023-34063)
vendor_vmware·2024-01-16·CVSS 9.9
CVE-2023-34063 [CRITICAL] VMware Aria Automation (formerly vRealize Automation) updates address a Missing Access Control vulnerability (CVE-2023-34063)
VMSA-2024-0001: VMware Aria Automation (formerly vRealize Automation) updates address a Missing Access Control vulnerability (CVE-2023-34063)
Aria Automation contains a Missing Access Control vulnerability. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.9.
CVEs: CVE-2023-34063
Affected products: VMware Aria, VMware Cloud Foundation
No detection rules found.
No public exploits indexed.
2024-01-16
Published