EXPOSURES › CVE-2023-20887
CVE-2023-20887
HIGH ⌖ ON CISA KEV · EXPLOITEDVMware Aria Operations for Networks command injection vulnerability allows remote code execution.
A command injection vulnerability in VMware Aria Operations for Networks allows a malicious actor with network access to execute arbitrary code remotely. This poses a significant risk to the security of networks and systems using this product. Organizations should update to the latest version or apply the patch to mitigate this risk. Remote code execution (RCE) is a severe vulnerability that can lead to full system compromise.
Shame score — The vulnerability was actively exploited, indicating a significant risk to the security of the product and the organizations using it.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware Aria Operations for Networks (formerly vRealize Network Insight) contains a command injection vulnerability that allows a malicious actor with network access to perform an attack resulting in remote code execution.
| PRODUCT | STATUS |
|---|---|
| VMware Government Services (VGS) VMware, Inc. |
Authorized |
| Workspace ONE VMware, Inc. |
Authorized |