CVE-2023-34039
VMWare Aria Operations for Networks SSH Private Key Exposure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
8Exploited in Wild
-Decision
Descriptions
Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to gain access to the Aria Operations for Networks CLI.
Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to gain access to the Aria Operations for Networks CLI.
VMWare Aria Operations for Networks (vRealize Network Insight) versions 6.0.0 through 6.10.0 do not randomize the SSH keys on virtual machine initialization. Since the key is easily retrievable, an attacker can use it to gain unauthorized remote access as the "support" (root) user.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-05-25 CVE Reserved
- 2023-08-29 CVE Published
- 2023-09-01 First Exploit
- 2025-02-13 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-327: Use of a Broken or Risky Cryptographic Algorithm
CAPEC
References (11)
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/175320 | 2023-10-24 | |
https://packetstorm.news/files/id/174452 | 2023-09-02 | |
https://github.com/Cyb3rEnthusiast/CVE-2023-34039 | 2023-09-03 | |
https://github.com/CharonDefalt/CVE-2023-34039 | 2023-09-01 | |
https://github.com/sinsinology/CVE-2023-34039 | 2023-09-01 | |
https://github.com/syedhafiz1234/CVE-2023-34039 | 2023-09-04 | |
https://github.com/adminxb/CVE-2023-34039 | 2023-11-10 | |
http://packetstormsecurity.com/files/175320/VMWare-Aria-Operations-For-Networks-SSH-Private-Key-Exposure.html | 2025-02-13 |
URL | Date | SRC |
---|---|---|
https://www.vmware.com/security/advisories/VMSA-2023-0018.html | 2023-08-29 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Vmware Search vendor "Vmware" | Aria Operations For Networks Search vendor "Vmware" for product "Aria Operations For Networks" | >= 6.2.0 < 6.11.0 Search vendor "Vmware" for product "Aria Operations For Networks" and version " >= 6.2.0 < 6.11.0" | - |
Affected
|