ZDI-CAN-17959: ZDI-23-055: VMware vRealize Network Insight createSupportBundle Command Injection Remote Code Execution Vulnerability
Published Jan 18, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VMware vRealize Network Insight. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
VMware vRealize Network Insight
Event History
Jan 18, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-17959?
ZDI-CAN-17959 has been classified with a high severity due to its potential for remote code execution.
2
How do I fix ZDI-CAN-17959?
To fix ZDI-CAN-17959, ensure that your VMware vRealize Network Insight is updated to the latest patched version provided by VMware.
3
What type of attacks can ZDI-CAN-17959 enable?
ZDI-CAN-17959 allows remote attackers to execute arbitrary code on vulnerable installations without requiring authentication.
4
Which software versions are affected by ZDI-CAN-17959?
ZDI-CAN-17959 affects installations of VMware vRealize Network Insight across all versions.
5
Is authentication needed to exploit ZDI-CAN-17959?
No, authentication is not required to exploit ZDI-CAN-17959, making it particularly dangerous.