Improper Authentication in Aria Operations for Logs (formerly vRealize Log Insight) - CVE-2023-34051

 

Improper Authentication in Aria Operations for Logs (formerly vRealize Log Insight) - CVE-2023-34051

Published: October 20, 2023 / Updated: October 25, 2023


Vulnerability identifier: #VU82267
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-34051
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in the authentication process. A remote non-authenticated attacker can bypass authentication process and inject files into the operating system of an impacted appliance.

Successful exploitation of the vulnerability can result in remote code execution and full compromise of the affected appliance.


Affected software

Aria Operations for Logs (formerly vRealize Log Insight)

How to mitigate CVE-2023-34051

Install updates from vendor's website.

Aria Operations for Logs (formerly vRealize Log Insight) - update to 8.14

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins