CVE-2023-34063Missing Authorization in Vmware Aria Automation

Severity
8.3HIGHNVD
CNA9.9
EPSS
0.2%
top 61.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 16

Description

Aria Automation contains a Missing Access Control vulnerability. An authenticated malicious actor may exploit this vulnerability leading to unauthorized access to remote organizations and workflows.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:HExploitability: 2.8 | Impact: 5.5

Affected Packages2 packages

NVDvmware/aria_automation10 versions+9
NVDvmware/cloud_foundation4.0, 5.0+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-fcww-v4hr-rgfr: Aria Automation contains a Missing Access Control vulnerability2024-01-16
CVEList
CVE-2023-34063: Aria Automation contains a Missing Access Control vulnerability2024-01-16

📋Vendor Advisories

1
VMware
VMware Aria Automation (formerly vRealize Automation) updates address a Missing Access Control vulnerability (CVE-2023-34063)2024-01-16
CVE-2023-34063 — Missing Authorization in Vmware | cvebase