Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

VMware confirmed on 31 August 2023 that exploit code had been published for CVE-2023-34039, a critical authentication-bypass vulnerability in VMware Aria Operations for Networks. The flaw could let an attacker with network access bypass SSH authentication and reach the product’s command-line interface. Administrators should check their installed release against VMware’s VMSA-2023-0018.1 advisory and apply the fix specified for their environment. VMware lists version 6.11 as unaffected and provides no workaround.

What CVE-2023-34039 affects

CVE-2023-34039 affects VMware Aria Operations for Networks, formerly known as vRealize Network Insight. VMware describes the cause as a lack of unique cryptographic key generation and assigns the vulnerability a maximum CVSSv3 base score of 9.8. That score communicates severity; it is not a count of affected organizations or evidence that attackers exploited the flaw.

NHS England Digital says versions before 6.11 are affected. VMware’s response matrix lists version 6.11 as unaffected. Check the exact installed version and build against the vendor’s advisory rather than assuming that a particular upgrade applies to every deployment.

How the attack works

VMware says a malicious actor with network access could bypass SSH authentication and gain access to the product’s command-line interface. The described access requirement is network access, not a prior administrative login.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

SecurityWeek attributed exploit code and root-cause analysis to researcher Sina Kheirkhah of SinSinology. Kheirkhah characterized the issue as VMware failing to regenerate keys, while VMware’s formal description is an authentication bypass caused by a lack of unique cryptographic key generation. His explanation is a researcher’s characterization, not a substitute for the vendor’s advisory.

What published exploit code does—and does not—establish

VMware updated its advisory on 31 August 2023 to confirm that exploit code had been published. NHS England Digital added a proof-of-concept update on 4 September 2023. SecurityWeek reported on the publication on 1 September 2023.

Publication of exploit code is not, by itself, proof of exploitation in the wild. The cited sources confirm code publication but do not establish current attacker activity, the number of exposed installations, or the number of victims. VMware’s stated precondition is network access to Aria Operations for Networks; the sources do not quantify how many installations were reachable by attackers.

How to check and patch the vulnerability

  1. Identify the product and installed build. Confirm whether the environment runs VMware Aria Operations for Networks and record its exact version and build.
  2. Compare the release with VMware’s advisory. Review VMSA-2023-0018.1. VMware lists 6.11 as unaffected; NHS England Digital describes releases before 6.11 as affected.
  3. Use VMware’s release-specific fix guidance. For affected 6.x installations, VMware directs administrators to KB94152 for fixed-version guidance. Follow the instructions applicable to the installed build and environment.
  4. Apply the vendor update. VMware lists no workaround, so use the applicable fixed update rather than treating network isolation as a vendor-approved substitute.
  5. Check the separate vulnerability in the same advisory. Review whether CVE-2023-20890 also applies to the installation and address it through VMware’s guidance as needed.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Do not confuse CVE-2023-34039 with CVE-2023-20890

VMware’s advisory covers two distinct vulnerabilities. CVE-2023-34039 is the SSH authentication-bypass flaw described above. CVE-2023-20890 is a separate arbitrary file-write vulnerability with a maximum CVSSv3 base score of 7.2. VMware says CVE-2023-20890 requires authenticated administrative access and could potentially enable remote code execution. Those authentication requirements apply to CVE-2023-20890, not to CVE-2023-34039.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.