Impact of CVE-2024-39894 on Aria Operations for Networks
search cancel

Impact of CVE-2024-39894 on Aria Operations for Networks

book

Article ID: 412301

calendar_today

Updated On:

Products

VCF Operations for Networks

Issue/Introduction

CVE-2024-39894 affects OpenSSH versions 9.5 to 9.7, as per https://nvd.nist.gov/vuln/detail/CVE-2024-39894

Environment

VMware Aria Operations for Networks

Cause

As per the CVE description, "OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur."

Resolution

VMware Aria Operations for Networks 6.14.x uses OpenSSH version 8.9p1 which is not impacted by CVE-2024-39894.