VDB
CVE-2024-38831
CVE-2024-38831
PUBLISHED
Es bestehen mehrere Schwachstellen in VMware Aria Operations. Ein lokaler Angreifer mit administrativen Rechten kann diese Schwachstellen ausnutzen, um auf der Appliance, auf der VMware Aria Operations läuft, die Rechte zum Root-Benutzer zu erweitern.
EPSS 0.16% · 36.4th percentile
Risk Scores
EPSS Score
0.16%
36.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| VMware | VMware Aria Operations <8.18.2 | |
| Google Cloud Platform |
Timeline
- Nov 26, 2024 CVE Published
- Nov 26, 2024 PoC Published
- Nov 26, 2024 PoC Published
- Nov 26, 2024 PoC Published
- Nov 26, 2024 CVE Updated
- Nov 27, 2024 EPSS Score
- Dec 15, 2024 EPSS Score
- Jan 1, 2025 EPSS Score
- Jan 19, 2025 EPSS Score
- Jan 28, 2025 Coalition ESS Score
- Feb 5, 2025 EPSS Score
- Feb 22, 2025 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-3555.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-3555 advisory
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25199 advisory
- https://cloud.google.com/support/bulletins#gcp-2024-064 advisory