OpenSSL 3.0.x Vulnerabilities in Aria Operations and VCF Operations Telegraf Agents
search cancel

OpenSSL 3.0.x Vulnerabilities in Aria Operations and VCF Operations Telegraf Agents

book

Article ID: 444843

calendar_today

Updated On:

Products

VCF Operations

Issue/Introduction

Security scanners may flag vulnerabilities in the OpenSSL libraries bundled with the Telegraf agent (Salt-minion) managed by Aria Operations 8.18.6 or VCF Operations 9.0.2

Reported Vulnerabilities:

  • OpenSSL < 3.0.19 (High): CVE-2025-15467, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796.
  • OpenSSL < 3.0.20 (Critical): CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, CVE-2026-31789, CVE-2026-31790

Environment

  • VMware Aria Operations 8.18.6
  • VMware Cloud Foundation Operations 9.0.2.0

Resolution

Broadcom is aware of these OpenSSL CVEs.
Please refer to the release notes for existing and forthcoming product releases for any updates in relation to these CVEs. Should you require further information contact Broadcom Support.