ZDI-23-840: VMware Aria Operations for Networks createSupportBundle Command Injection Remote Code Execution Vulnerability
Published Jun 8, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VMware Aria Operations for Networks. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
VMware Aria Operations for Networks
Event History
Jun 8, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-840?
The severity of ZDI-23-840 is critical due to its potential for remote code execution without authentication.
2
How do I fix ZDI-23-840?
To fix ZDI-23-840, apply the latest security patch provided by VMware for Aria Operations for Networks.
3
Who is affected by ZDI-23-840?
ZDI-23-840 affects installations of VMware Aria Operations for Networks.
4
Can ZDI-23-840 be exploited remotely?
Yes, ZDI-23-840 can be exploited remotely by attackers without the need for authentication.
5
What type of vulnerability is ZDI-23-840?
ZDI-23-840 is a remote code execution vulnerability that allows attackers to execute arbitrary code.