← Vulnerability feed

Vulnerability record · CVE-2023-34039 · published 29 August 2023

CVE-2023-34039: VMware Aria Operations for Networks SSH authentication bypass

Vmware · Aria Operations For Networks

Aria Operations for Networks generates non-unique cryptographic keys, allowing SSH authentication to be bypassed. An attacker with network reachability can log into the appliance CLI without valid credentials, which exposes a management interface that can lead to further compromise.

9.8 CVSS 3.1 Critical EPSS 67% · top 0.7% CWE-327 · Broken cryptographic algorithm
9.8CVSS 3.1 base score
67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to gain access to the Aria Operations for Networks CLI.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required, high EPSS, and public exploit references make this an urgent management-plane exposure.

What it is

Aria Operations for Networks generates non-unique cryptographic keys, allowing SSH authentication to be bypassed. An attacker with network reachability can log into the appliance CLI without valid credentials, which exposes a management interface that can lead to further compromise.

Impact

An unauthenticated attacker gains CLI access to the Aria Operations for Networks appliance, enabling configuration changes, data access and potential remote code execution on the management plane.

Attack surface

Reachable over the network via SSH to the Aria Operations for Networks appliance; no authentication or user interaction is required per the CVSS vector (AV:N/PR:N/UI:N).

Exploitation

Not listed in CISA KEV, but EPSS is high (0.67, 99th percentile) and public exploit references exist, including an SSH private key exposure write-up, indicating practical exploitation is likely.

What to do

  • Apply the vendor patch from VMware advisory VMSA-2023-0018 immediately.
  • Restrict SSH access to Aria Operations for Networks to trusted management networks and jump hosts.
  • Rotate any SSH keys or credentials associated with the appliance after patching.
  • Monitor for unauthorized CLI logins and configuration changes on the appliance.
  • If patching is delayed, isolate the appliance from untrusted networks.

Detection

  • Alert on SSH logins to Aria Operations for Networks from unexpected source IPs or at unusual times.
  • Audit appliance CLI command history and configuration changes for unauthorized activity.
  • Hunt for use of the publicly exposed SSH private key material against the appliance.
  • Review network flows to the appliance's SSH port from outside approved management segments.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-34039 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-20887VMware Aria Operations for Networks command injectionVMware Aria Operations for Networks contains a command injection flaw (CWE-77) that lets a remote attacker execute arbitrary commands on the applianc…KEVEPSS 98%analysed7.8CVE-2024-22237Vmware aria operations for networks improper privilege management vulnerabilityAria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may expl…EPSS 0.25%7.8CVE-2024-22239Vmware aria operations for networks improper privilege management vulnerabilityAria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may expl…EPSS 0.21%7.2CVE-2023-20890Vmware aria operations for networks path traversal vulnerabilityAria Operations for Networks contains an arbitrary file write vulnerability. An authenticated malicious actor with administrative access to VMware Ar…EPSS 20%4.9CVE-2024-22240Vmware aria operations for networks vulnerabilityAria Operations for Networks contains a local file read vulnerability. A malicious actor with admin privileges may exploit this vulnerability leading…EPSS 0.62%4.8CVE-2024-22241Vmware aria operations for networks cross-site scripting vulnerabilityAria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges can inject a malicious payload in…EPSS 38%4.8CVE-2024-22238Vmware aria operations for networks cross-site scripting vulnerabilityAria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges may be able to inject malicious c…EPSS 0.50%

Source: NIST National Vulnerability Database (record CVE-2023-34039), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.