CVE-2023-20889: Command Injection
Aria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in information disclosure.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-20889?
CVE-2023-20889 is an information disclosure vulnerability in VMware Aria Operations for Networks.
What is the severity of CVE-2023-20889?
The severity of CVE-2023-20889 is high with a CVSS score of 7.5.
How does CVE-2023-20889 affect VMware Aria Operations for Networks?
CVE-2023-20889 allows a malicious actor with network access to perform a command injection attack and gain unauthorized access to sensitive information.
Which versions of VMware Aria Operations for Networks are affected by CVE-2023-20889?
VMware Aria Operations for Networks versions 6.2.0 to 6.10.0 are affected by CVE-2023-20889.
Is there a fix for CVE-2023-20889?
Yes, VMware has released a security advisory with mitigation instructions for CVE-2023-20889. Please refer to the reference link for more details.