Database/Control plane, storage & DevOps
VMware Aria Operations (command injection during assisted migration): An unauthenticated attacker injects commands
Impact
An unauthenticated attacker injects commands and reaches remote code execution on Aria Operations while a support-assisted product migration is running. The exposure window is operational rather than permanent - it opens exactly when you are mid-migration and least able to respond.
Who can reach it
Unauthenticated network access during a support-assisted migration window.
What to do
Apply the patches in Broadcom advisory 36947 before undertaking any assisted migration. If a migration is already in flight, restrict network access to the Aria Operations appliance for its duration.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.