CVE-2023-20887
Vmware Aria Operations for Networks Command Injection Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.
Required action
Apply updates per vendor instructions.
CISA notes
https://www.vmware.com/security/advisories/VMSA-2023-0012.html; https://nvd.nist.gov/vuln/detail/CVE-2023-20887
Description
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAffected Products
| Vendor | Product | Affected versions |
|---|---|---|
| - | Aria Operations for Networks (Formerly vRealize Network Insight) | Aria Operations for Networks (Formerly vRealize Network Insight) 6.x |
References
2 LinksRecord Details
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.