← Vulnerability feed

Vulnerability record · CVE-2024-22239 · published 6 February 2024

CVE-2024-22239: Vmware aria operations for networks improper privilege management vulnerability

Vmware · Aria Operations For Networks

Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may exploit this vulnerability to escalate privileges to gain regular shell access.

7.8 CVSS 3.1 High EPSS 0.21% · top 89.5% CWE-269 · Improper privilege management
7.8CVSS 3.1 base score
0.21%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may exploit this vulnerability to escalate privileges to gain regular shell access.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-22239 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-20887VMware Aria Operations for Networks command injectionVMware Aria Operations for Networks contains a command injection flaw (CWE-77) that lets a remote attacker execute arbitrary commands on the applianc…KEVEPSS 98%analysed9.8CVE-2023-34039VMware Aria Operations for Networks SSH authentication bypassAria Operations for Networks generates non-unique cryptographic keys, allowing SSH authentication to be bypassed. An attacker with network reachabili…EPSS 67%analysed7.8CVE-2024-22237Vmware aria operations for networks improper privilege management vulnerabilityAria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may expl…EPSS 0.25%7.2CVE-2023-20890Vmware aria operations for networks path traversal vulnerabilityAria Operations for Networks contains an arbitrary file write vulnerability. An authenticated malicious actor with administrative access to VMware Ar…EPSS 20%4.9CVE-2024-22240Vmware aria operations for networks vulnerabilityAria Operations for Networks contains a local file read vulnerability. A malicious actor with admin privileges may exploit this vulnerability leading…EPSS 0.62%4.8CVE-2024-22241Vmware aria operations for networks cross-site scripting vulnerabilityAria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges can inject a malicious payload in…EPSS 38%4.8CVE-2024-22238Vmware aria operations for networks cross-site scripting vulnerabilityAria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges may be able to inject malicious c…EPSS 0.50%9.9CVE-2026-84869ScreenConnect client allows unauthorized file transfer and execution in remote sessionsA flaw in the ConnectWise ScreenConnect client lets files be transferred and executed inside an active remote session without authorization or Host c…KEVEPSS 0.92%analysed

Source: NIST National Vulnerability Database (record CVE-2024-22239), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.