9.8
CVSSv3

CVE-2023-34039

Published: 29/08/2023 Updated: 09/01/2024
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to gain access to the Aria Operations for Networks CLI.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vmware aria operations for networks

Exploits

VMWare Aria Operations for Networks (vRealize Network Insight) versions 600 through 6100 do not randomize the SSH keys on virtual machine initialization Since the key is easily retrievable, an attacker can use it to gain unauthorized remote access as the "support" (root) user ...

Github Repositories

VMWare Aria Operations for Networks (vRealize Network Insight) Static SSH key RCE (CVE-2023-34039)

CVE-2023-34039 POC for CVE-2023-34039 VMWare Aria Operations for Networks (vRealize Network Insight) Static SSH key RCE Technical Analysis A root cause analysis of the vulnerability can be found on my blog: summoningteam/blog/vmware-vrealize-network-insight-rce-cve-2023-34039/

CVE-2023-34039

CVE-2023-34039 POC for CVE-2023-34039 VMWare Aria Operations for Networks (vRealize Network Insight) Static SSH key RCE Technical Analysis A root cause analysis of the vulnerability can be found on my blog: summoningteam/blog/vmware-vrealize-network-insight-rce-cve-2023-34039/

VMware exploit

CVE-2023-34039 POC for CVE-2023-34039 VMWare Aria Operations for Networks (vRealize Network Insight) Static SSH key RCE Technical Analysis A root cause analysis of the vulnerability can be found on my blog: summoningteam/blog/vmware-vrealize-network-insight-rce-cve-2023-34039/