Broadcom has released patches for vulnerabilities in VMware Aria, as these exploits could potentially result in credential theft.

Broadcom has released patches for vulnerabilities in VMware Aria, as these exploits could potentially result in credential theft.
Broadcom has released patches for vulnerabilities in VMware Aria, as these exploits could potentially result in credential theft.

Broadcom has issued security updates to address five vulnerabilities affecting VMware Aria Operations and Aria Operations for Logs. They caution customers that these flaws could be exploited by attackers to gain elevated access or access sensitive information.

Here’s a list of the identified vulnerabilities, which affect versions 8.x of the software:

Security researchers Maxime Escourbiac from Michelin CERT, along with Yassine Bengana and Quentin Ebel from Abicom, have been instrumental in detecting and reporting these vulnerabilities. It’s important to highlight that this same team identified two additional issues in the same product (CVE-2024-38832 and CVE-2024-38833) in late November 2024.

1All the vulnerabilities mentioned have been addressed in VMware Aria Operations and Aria Operations for Logs version 8.18.3. The virtualization services provider has not indicated that these issues have been exploited in the wild.

This advisory was released just days after Broadcom alerted users to a high-severity security flaw in VMware Avi Load Balancer (CVE-2025-22217, CVSS score: 8.6), which could potentially be exploited by malicious actors to gain access to databases.

Exit mobile version