Junglewise Threat Intelligence

CVE-2023-20887: Vmware Aria Operations for Networks Command Injection Vulnerability

CVE-2023-20887 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-06-22

Vendors: VMware.

Executive brief

VMware Aria Operations for Networks (formerly vRealize Network Insight) contains a command injection vulnerability due to improper neutralization of special elements. A remote, unauthenticated attacker with network access can exploit this to execute arbitrary commands on the underlying operating system.

Affected products

  • VMware Aria Operations for Networks 6.2.0 - 6.10.0
  • VMware vRealize Network Insight 6.2.0 - 6.10.0

Timeline

  • 2023-06-07: disclosed: NVD Published Date
  • 2023-06-22: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-06-22: advisory: VMSA-2023-0012 published by VMware
  • 2023-06-22: exploited: Reported as exploited in the wild per CISA KEV entry