ZDI-CAN-19980: ZDI-23-840: VMware Aria Operations for Networks createSupportBundle Command Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VMware Aria Operations for Networks. Authentication is not required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-19980?
ZDI-CAN-19980 is classified as a critical vulnerability due to its ability to allow remote code execution without authentication.
How do I fix ZDI-CAN-19980?
To fix ZDI-CAN-19980, apply the latest security patch provided by VMware for Aria Operations for Networks.
What impact does ZDI-CAN-19980 have on VMware Aria Operations for Networks?
ZDI-CAN-19980 allows attackers to execute arbitrary code, potentially compromising the entire system and its data.
Who is affected by ZDI-CAN-19980?
Any installations of VMware Aria Operations for Networks that have not been patched are vulnerable to ZDI-CAN-19980.
Is authentication required to exploit ZDI-CAN-19980?
No, authentication is not required to exploit ZDI-CAN-19980, making it particularly dangerous.