HomeUpdatesBroadcom fixes vulnerabilities in VMware Aria products

Broadcom patches vulnerabilities in VMware Aria products

Broadcom has released updates to fix five vulnerabilities affecting VMware Aria Operations and Aria Operations for Logs . The vulnerabilities could allow attackers to gain elevated access to systems or steal sensitive information.

See also: NCSC calls on vendors to eliminate vulnerabilities

VMware Aria Broadcom vulnerabilities

According to the company, the vulnerabilities affect versions 8.x of the software. Let's take a closer look at them:

CVE-2025-22218 (CVSS score: 8.5): An attacker can use the vulnerability to obtain the credentials of a VMware product that is integrated with VMware Aria Operations for Logs. However, to exploit the vulnerability, the attacker must have View Only Admin privileges.

CVE-2025-22219 (CVSS Score: 6.8/10): An attacker with non-administrative privileges could inject a malicious script, which could lead to arbitrary operations as an admin user, via a stored cross-site scripting (XSS) attack.

CVE-2025-22220 (CVSS score: 4.3/10): A malicious actor with non-administrative privileges and network access to the Aria Operations for Logs API may be able to perform certain operations as an admin user.

CVE-2025-22221 (CVSS score: 5.2/10): Attackers with administrator privileges in VMware Aria Operations for Logs can inject a malicious script that could be executed in a victim's browser when performing a delete action in Agent Configuration.

CVE-2025-22222 (CVSS score: 7.7/10): An attacker with non-administrative privileges can retrieve credentials for an outbound plugin, if a valid service credential ID is known.

See also: Aquabotv3 botnet exploits vulnerability in Mitel phones

Broadcom patches vulnerabilities in VMware Aria products

All vulnerabilities have been fixed in VMware Aria Operations and Aria Operations for Logs version 8.18.3. At this time, there is no evidence that the above vulnerabilities have been exploited.

It is important for organizations using VMware Aria Operations and Aria Operations for Logs to take immediate action and apply the necessary updates provided by Broadcom. In addition, companies should review their security measures and protocols to ensure comprehensive protection against potential cyber threats. It is also recommended to monitor for any suspicious activity and promptly respond to any security incidents that may arise.

See also: Zyxel zero-day vulnerability allows execution of arbitrary commands

Broadcom, for its part, remains committed to the security of its products and urges customers to regularly check for updates and apply them as soon as possible. Therefore, it is important for enterprises to remain vigilant, be informed of potential threats and take the necessary measures to secure their infrastructure.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS