By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Broadcom Patches VMware Aria Flaws – Exploits May Lead to Credential Theft
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Broadcom Patches VMware Aria Flaws – Exploits May Lead to Credential Theft
Tech News

Broadcom Patches VMware Aria Flaws – Exploits May Lead to Credential Theft

By Viral Trending Content 3 Min Read
Share
SHARE

Jan 31, 2025Ravie LakshmananVulnerability / Data Security

VMware Aria Flaws

Broadcom has released security updates to patch five security flaws impacting VMware Aria Operations and Aria Operations for Logs, warning customers that attackers could exploit them to gain elevated access or obtain sensitive information.

The list of identified flaws, which impact versions 8.x of the software, is below –

  • CVE-2025-22218 (CVSS score: 8.5) – A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated with VMware Aria Operations for Logs
  • CVE-2025-22219 (CVSS score: 6.8) – A malicious actor with non-administrative privileges may be able to inject a malicious script that may lead to arbitrary operations as admin user via a stored cross-site scripting (XSS) attack
  • CVE-2025-22220 (CVSS score: 4.3) – A malicious actor with non-administrative privileges and network access to Aria Operations for Logs API may be able to perform certain operations in the context of an admin user
  • CVE-2025-22221 (CVSS score: 5.2) – A malicious actor with admin privileges to VMware Aria Operations for Logs may be able to inject a malicious script that could be executed in a victim’s browser when performing a delete action in the Agent Configuration
  • CVE-2025-22222 (CVSS score: 7.7) – A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin if a valid service credential ID is known
Cybersecurity

Security researchers Maxime Escourbiac from Michelin CERT, and Yassine Bengana and Quentin Ebel from Abicom and part of the Michelin CERT team for detecting and reporting the flaws. It’s worth noting that the same team spotted two other shortcomings in the same product (CVE-2024-38832 and CVE-2024-38833) in late November 2024.

All the aforementioned vulnerabilities have been patched in VMware Aria Operations and Aria Operations for Logs version 8.18.3. The virtualization services provider makes no mention of these issues being exploited in the wild.

The advisory comes days after Broadcom warned of a high-severity security flaw in VMware Avi Load Balancer (CVE-2025-22217, CVSS score: 8.6) that could be weaponized by malicious actors to gain database access.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Microsoft’s MDASH AI System Finds 16 Windows Flaws Fixed in Patch Tuesday

Honor 600 Review: The Android iPhone

What It Will Take to Make AI Sustainable

The Case for Autonomous Validation

Apple AI Pin Specs Leak: Dual Cameras, No Screen & More

TAGGED: Broadcom, Cyber Security, Cybersecurity, data security, Internet, Security Update, software patch, Threat Intelligence, VMware, Vulnerability
Share This Article
Facebook Twitter Copy Link
Previous Article Trump warns tariffs on Canada and Mexico are coming on Saturday
Next Article RCO Finance’s token presale hits $12M as demand for its crypto AI platform surges
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

US stocks today: S&P 500, Nasdaq boosted by chips to record closing highs; hot inflation report kills rate-cut hopes
Business
Europe watches Beijing summit from the sidelines and fears the worst
World News
Ethena price: ENA dips despite 5-week peak in whale activity
Crypto
Ledger And Consensys Delay US IPO Dreams As Crypto Conditions Turn Unfriendly
Crypto
How could extreme weather affect World Cup 2026?
World News
Chinese Communist Regime Restricts Press Access for Trump’s Visit
Politics
Hayden Panettiere’s Ex Wladimir Klitschko: Their Rocky Relationship From First Romance to Co-Parents
Celebrity

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Investing £5 a day could help me build a second income of £329 a month!

Brussels unveils plans for a European Degree but struggles to explain why

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
Trump evokes more anger and fear from Democrats than Biden does from Republicans, AP-NORC poll shows
March 28, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?