CVE-2023-20887: Vmware Aria Operations for Networks Command Injection Vulnerability
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution.
Other sources
VMware Aria Operations for Networks (formerly vRealize Network Insight) contains a command injection vulnerability that allows a malicious actor with network access to perform an attack resulting in remote code execution.
— CISA
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-20887?
CVE-2023-20887 is a command injection vulnerability in Vmware Aria Operations for Networks that allows remote code execution.
Who is affected by CVE-2023-20887?
Users of VMware Aria Operations for Networks versions 6.2.0 to 6.10.0 are affected by CVE-2023-20887.
What is the severity of CVE-2023-20887?
CVE-2023-20887 has a severity rating of 9.8 (critical).
How can a malicious actor exploit CVE-2023-20887?
A malicious actor with network access can exploit CVE-2023-20887 by performing a command injection attack.
How can I fix CVE-2023-20887?
To fix CVE-2023-20887, users should apply the necessary patch or upgrade to a non-vulnerable version of VMware Aria Operations for Networks.