First published: Wed Jun 07 2023(Updated: )
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution.
Credit: security@vmware.com security@vmware.com security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Aria Operations for Networks | ||
Vmware Vrealize Network Insight | >=6.2.0<=6.10.0 | |
VMware Aria Operations for Networks | >=6.2.0<=6.10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-20887 is a command injection vulnerability in Vmware Aria Operations for Networks that allows remote code execution.
Users of VMware Aria Operations for Networks versions 6.2.0 to 6.10.0 are affected by CVE-2023-20887.
CVE-2023-20887 has a severity rating of 9.8 (critical).
A malicious actor with network access can exploit CVE-2023-20887 by performing a command injection attack.
To fix CVE-2023-20887, users should apply the necessary patch or upgrade to a non-vulnerable version of VMware Aria Operations for Networks.