CVE-2023-20888: High severity vmware vrealize network insight vulnerability
Published Jun 7, 2023
·Updated
Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations for Networks and valid 'member' role credentials may be able to perform a deserialization attack resulting in remote code execution.
Affected Software
1 affected component
VMware vRealize Network Insight>=6.2.0<=6.10.0
Remediation
Event History
Jun 7, 2023
CVE Published
via MITRE·02:18 PM
Data Sourced
via MITRE·02:18 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2023-20888?
CVE-2023-20888 is an authenticated deserialization vulnerability in Aria Operations for Networks.
2
How does CVE-2023-20888 affect VMware Aria Operations for Networks?
CVE-2023-20888 allows a malicious actor with network access to perform a deserialization attack resulting in remote code execution in VMware Aria Operations for Networks.
3
What is the severity of CVE-2023-20888?
CVE-2023-20888 has a severity rating of 8.8 (high).
4
How can I fix CVE-2023-20888?
To fix CVE-2023-20888, update to a version of VMware Aria Operations for Networks between 6.2.0 and 6.10.0.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-20888?
The CWE ID for CVE-2023-20888 is 502.