Tenable scanner detecting a CVE open for openssh version less than 9 against Aria Operations for Logs
search cancel

Tenable scanner detecting a CVE open for openssh version less than 9 against Aria Operations for Logs

book

Article ID: 428912

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

Tenable scanner reports a vulnerable openssh version on Aria Operations for logs because the version is less than 9.

Environment

Aria Operations for Logs 8.18.5

Cause

The scanner shows the reference to CVEs CVE-2024-39894 and CVE-2024-6387 from Nessus Plugin ID 201194 and is detecting a version of openssh less than the recommended version of openssh for these two vulnerabilities.

Resolution

VMware By Broadcom is aware of CVE-2024-39894.
Please refer to the release notes for existing and forthcoming product releases for any updates in relation to this CVE.
Should you require further information please contact Broadcom Support.

VMware By Broadcom is aware of CVE-2024-6387.
Please refer to the release notes for existing and forthcoming product releases for any updates in relation to this CVE.
Should you require further information please contact Broadcom Support.

Additional Information

Please see the following KBs for more information: