First published: Wed Jun 07 2023(Updated: )
Aria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in information disclosure.
Credit: security@vmware.com security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Vmware Vrealize Network Insight | >=6.2.0<=6.10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-20889 is an information disclosure vulnerability in VMware Aria Operations for Networks.
The severity of CVE-2023-20889 is high with a CVSS score of 7.5.
CVE-2023-20889 allows a malicious actor with network access to perform a command injection attack and gain unauthorized access to sensitive information.
VMware Aria Operations for Networks versions 6.2.0 to 6.10.0 are affected by CVE-2023-20889.
Yes, VMware has released a security advisory with mitigation instructions for CVE-2023-20889. Please refer to the reference link for more details.