Skip to content
COOEY

EXPOSURES › CVE-2023-20887

CVE-2023-20887

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-06-22 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-20887 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

VMware Aria Operations for Networks command injection vulnerability allows remote code execution.

A command injection vulnerability in VMware Aria Operations for Networks allows a malicious actor with network access to execute arbitrary code remotely. This poses a significant risk to the security of networks and systems using this product. Organizations should update to the latest version or apply the patch to mitigate this risk. Remote code execution (RCE) is a severe vulnerability that can lead to full system compromise.

Shame score — The vulnerability was actively exploited, indicating a significant risk to the security of the product and the organizations using it.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

VMware Aria Operations for Networks (formerly vRealize Network Insight) contains a command injection vulnerability that allows a malicious actor with network access to perform an attack resulting in remote code execution.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
VMware Government Services (VGS)
VMware, Inc.
Authorized
Workspace ONE
VMware, Inc.
Authorized