First published: Wed Jun 07 2023(Updated: )
Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations for Networks and valid 'member' role credentials may be able to perform a deserialization attack resulting in remote code execution.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Vmware Vrealize Network Insight | >=6.2.0<=6.10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-20888 is an authenticated deserialization vulnerability in Aria Operations for Networks.
CVE-2023-20888 allows a malicious actor with network access to perform a deserialization attack resulting in remote code execution in VMware Aria Operations for Networks.
CVE-2023-20888 has a severity rating of 8.8 (high).
To fix CVE-2023-20888, update to a version of VMware Aria Operations for Networks between 6.2.0 and 6.10.0.
The CWE ID for CVE-2023-20888 is 502.