CVE-2023-20878: High severity vmware vcenter server and cloud foundation vulnerability
VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can execute arbitrary commands and disrupt the system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-20878?
CVE-2023-20878 is a deserialization vulnerability in VMware Aria Operations that allows a malicious actor with administrative privileges to execute arbitrary commands and disrupt the system.
Which software versions are affected by CVE-2023-20878?
CVE-2023-20878 affects VMware Cloud Foundation versions 4.0 to 4.5, Vmware Vrealize Operations version 8.6.0, and Vmware Vrealize Operations versions 8.6.0-hotfix1 to 8.10.0-hotfix2.
What is the severity of CVE-2023-20878?
CVE-2023-20878 has a severity rating of 7.2 (High).
How can a malicious actor exploit CVE-2023-20878?
A malicious actor with administrative privileges can exploit CVE-2023-20878 by executing arbitrary commands.
Is there a fix for CVE-2023-20878?
Yes, VMware has released a security advisory with recommended patches and mitigations for CVE-2023-20878. Please refer to the official VMware security advisory for more information.