---
cve: "CVE-2023-34051"
severity: "CRITICAL"
cvss: 9.8
epss: "44.7%"
vendor: "n/a"
kev: false
exploited: false
published: "2023-10-20 05:15:07"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-17T22:16:33+02:00"
---

# CVE-2023-34051

> 9.8 CRITICAL

## Beschreibung

VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <https://www.vmware.com/security/advisories/VMSA-2023-0021.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2023-34051) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
