PT-2024-1682 · Vmware · Vmware Aria Operations For Networks

Harsh Jaiswal

+1

·

Published

2024-02-06

·

Updated

2024-02-10

·

CVE-2024-22240

CVSS v2.0

6.1

Medium

VectorAV:N/AC:L/Au:M/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions VMware Aria Operations for Networks (affected versions not specified)
Description The issue is related to a local file read vulnerability in VMware Aria Operations for Networks. This vulnerability can be exploited by a malicious actor with admin privileges, potentially leading to unauthorized access to sensitive information. The vulnerability is associated with the use of files and directories accessible to external parties.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Files Accessible to External Parties

Weakness Enumeration

Related Identifiers

BDU:2024-01370
CVE-2024-22240

Affected Products

Vmware Aria Operations For Networks