CVE-2023-20887

CVE Published 2023-06-07
Related CWE(s) CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
Related Vendor(s) vmware
Related Product(s) aria_operations_for_networks, vrealize_network_insight
Exploitation Reported (CISA KEV) 2023-06-22
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References