{"id":1662,"date":"2025-01-31T10:03:34","date_gmt":"2025-01-31T10:03:34","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/01\/31\/vmware-aria-operations-vulnerabilities-let-attackers-perform-admin-operations\/"},"modified":"2025-01-31T10:03:34","modified_gmt":"2025-01-31T10:03:34","slug":"vmware-aria-operations-vulnerabilities-let-attackers-perform-admin-operations","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/01\/31\/vmware-aria-operations-vulnerabilities-let-attackers-perform-admin-operations\/","title":{"rendered":"VMware Aria Operations Vulnerabilities Let Attackers Perform Admin Operations\u00a0"},"content":{"rendered":"<p>    VMware Aria Operations Vulnerabilities Let Attackers Perform Admin Operations\u00a0<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Broadcom has addressed multiple vulnerabilities in its VMware Aria Operations for Logs and VMware Aria Operations products.\u00a0<\/p>\n<p>These vulnerabilities, identified as CVE-2025-22218, CVE-2025-22219, CVE-2025-22220, CVE-2025-22221, and CVE-2025-22222, pose significant risks, including unauthorized access to sensitive data and privilege escalation.\u00a0<\/p>\n<p>The vulnerabilities affect the following VMware products:<\/p>\n<ul class=\"wp-block-list\">\n<li>VMware Aria Operations for Logs (version 8.x)<\/li>\n<li>VMware Aria Operations (version 8.x)<\/li>\n<li>VMware Cloud Foundation (versions 4.x and 5.x)<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\"><strong>Vulnerabilities Overview<\/strong><\/h2>\n<p><strong>Credential Exposure via Improper Access Controls (CVE-2025-22218)<\/strong><\/p>\n<p>The most severe flaw, rated 8.5 CVSSv3, allows attackers with View Only Admin permissions to access credentials of integrated VMware products.\u00a0<\/p>\n<p>This vulnerability in Aria Operations for Logs could expose authentication details for linked services like vSphere or NSX, enabling lateral movement in compromised networks.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 88%,rgb(169,184,195) 100%)\"><strong><code>Collect Threat Intelligence with\u00a0TI Lookup\u00a0to Improve Your Company\u2019s Security\u00a0-\u00a0<a href=\"https:\/\/intelligence.any.run\/plans\/?utm_source=csn_jan&amp;utm_medium=article&amp;utm_campaign=ti&amp;utm_content=plans&amp;utm_content=linktotiplans&amp;utm_term=280125\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Get 50 Free Request<\/a><\/code><\/strong><\/p>\n<p><strong>Stored XSS-to-Admin Takeover Chain (CVE-2025-22219, CVE-2025-22221)<\/strong><\/p>\n<p>Two cross-site scripting (XSS) vulnerabilities (CVSS 6.8 and 5.2) enable privilege escalation through crafted payloads.\u00a0 Attackers with basic privileges could inject malicious scripts into log management interfaces, potentially hijacking admin sessions.\u00a0<\/p>\n<p>Notably, CVE-2025-22221 requires admin privileges but could propagate malware via agent configurations.<\/p>\n<p><strong>Logs broken access control vulnerability (CVE-2025-22220)<\/strong><\/p>\n<p>This moderate-severity flaw (CVSS 4.3) permits non-admin users with network access to the Aria Operations for Logs API to execute admin-level operations, potentially modifying audit trails or exfiltrating sensitive log data.<\/p>\n<p><strong>Information disclosure vulnerability (CVE-2025-22222)<\/strong><\/p>\n<p>Aria Operations contains a 7.7 CVSS-rated information disclosure flaw where non-admin users could retrieve credentials for outbound plugins using known service credential IDs, compromising integrated third-party services.<\/p>\n<p>Broadcom credited Maxime Escourbiac, Yassine Bengana, Quentin Ebel, and their teams at Michelin CERT and Abicom for responsibly disclosing these issues.<\/p>\n<p>These vulnerabilities allow attackers to perform admin-level operations or access sensitive data, even with limited privileges, making them particularly dangerous in enterprise environments where these products are widely deployed.<\/p>\n<p><strong>Resolution and Mitigation<\/strong><\/p>\n<p>Broadcom <a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/25329\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">strongly recommends<\/a> applying the patches listed in the advisory\u2019s response matrix:<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<tbody>\n<tr>\n<td><strong>Product<\/strong><\/td>\n<td><strong>Fixed Version<\/strong><\/td>\n<td><strong>Severity<\/strong><\/td>\n<td><strong>CVEs Addressed<\/strong><\/td>\n<\/tr>\n<tr>\n<td>VMware Aria Operations for Logs<\/td>\n<td>8.18.3<\/td>\n<td>Important<\/td>\n<td>CVE-2025-22218, CVE-2025-22219, CVE-2025-22220, CVE-2025-22221<\/td>\n<\/tr>\n<tr>\n<td>VMware Aria Operations<\/td>\n<td>8.18.3<\/td>\n<td>Important<\/td>\n<td>CVE-2025-22222<\/td>\n<\/tr>\n<tr>\n<td>VMware Cloud Foundation<\/td>\n<td>KB92148<\/td>\n<td>Important<\/td>\n<td>All listed CVEs<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>Organizations using affected products should prioritize updating to the latest versions to prevent potential exploitation of these vulnerabilities.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>For Daily Security Updates! Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMOffpwsw1Oq_Aw\" target=\"_blank\" rel=\"noreferrer noopener\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>, and\u00a0<a href=\"https:\/\/x.com\/The_Cyber_News\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/vmware-aria-operations-vulnerabilities-admin\/\">VMware Aria Operations Vulnerabilities Let Attackers Perform Admin Operations\u00a0<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/vmware-aria-operations-vulnerabilities-admin\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>VMware Aria Operations Vulnerabilities Let Attackers Perform Admin Operations\u00a0 Broadcom has addressed multiple vulnerabilities in its VMware Aria Operations for Logs and VMware Aria Operations products.\u00a0 These vulnerabilities, identified as CVE-2025-22218, CVE-2025-22219, CVE-2025-22220, CVE-2025-22221, and CVE-2025-22222, pose significant risks, including unauthorized access to sensitive data and privilege escalation.\u00a0 The vulnerabilities affect the following VMware products: [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648],"tags":[130],"class_list":["post-1662","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/1662"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=1662"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/1662\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=1662"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=1662"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=1662"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}