CVE-2024-38831
HIGHVmware Aria Operations < 8.18.2 - Command Injection
Title source: ruleDescription
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges can insert malicious commands into the properties file to escalate privileges to a root user on the appliance running VMware Aria Operations.
Scores
CVSS v3
7.8
EPSS
0.0012
EPSS Percentile
30.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-77
Status
published
Affected Products (2)
vmware/aria_operations
< 8.18.2
vmware/cloud_foundation
< 5.2
Timeline
Published
Nov 26, 2024
Tracked Since
Feb 18, 2026