VMware Aria Operations contains a local privilege escalation vulnerability.  A malicious actor with local administrative privileges can insert malicious commands into the properties file to escalate privileges to  a root user on the appliance running VMware Aria Operations.

Subscriptions

Vendors Products
Aria Operations Subscribe
Cloud Foundation Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-37706 VMware Aria Operations contains a local privilege escalation vulnerability.  A malicious actor with local administrative privileges can insert malicious commands into the properties file to escalate privileges to  a root user on the appliance running VMware Aria Operations.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 14 May 2025 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Vmware cloud Foundation
CPEs cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*
Vendors & Products Vmware cloud Foundation

Tue, 26 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Vmware
Vmware aria Operations
Weaknesses CWE-77
CPEs cpe:2.3:a:vmware:aria_operations:*:*:*:*:*:*:*:*
Vendors & Products Vmware
Vmware aria Operations
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 26 Nov 2024 12:00:00 +0000

Type Values Removed Values Added
Description VMware Aria Operations contains a local privilege escalation vulnerability.  A malicious actor with local administrative privileges can insert malicious commands into the properties file to escalate privileges to  a root user on the appliance running VMware Aria Operations.
Title Local privilege escalation vulnerability (CVE-2024-38831)
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2024-11-26T15:06:18.650Z

Reserved: 2024-06-19T22:32:07.790Z

Link: CVE-2024-38831

cve-icon Vulnrichment

Updated: 2024-11-26T15:06:14.373Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-26T12:15:18.590

Modified: 2025-05-14T16:43:22.730

Link: CVE-2024-38831

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses