ZDI-23-055: VMware vRealize Network Insight createSupportBundle Command Injection Remote Code Execution Vulnerability
Published Jan 18, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VMware vRealize Network Insight. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
VMware vRealize Network Insight
Event History
Jan 18, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-055?
The severity of ZDI-23-055 is critical due to its potential for remote code execution without authentication.
2
How do I fix ZDI-23-055?
To fix ZDI-23-055, you should apply the latest security patches provided by VMware for vRealize Network Insight.
3
What versions of VMware vRealize Network Insight are affected by ZDI-23-055?
ZDI-23-055 affects all installations of VMware vRealize Network Insight regardless of version.
4
Can ZDI-23-055 be exploited remotely?
Yes, ZDI-23-055 can be exploited remotely without the need for authentication.
5
What types of attacks can be carried out using ZDI-23-055?
Exploitation of ZDI-23-055 allows attackers to execute arbitrary code on affected systems.