CVE-2023-20887

Aria Operations for Networks (Formerly vRealize Network Insight)

Published 7 Jun 2023 · updated 17 Jun 2026 · Analyzed

9.8 Critical · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 22 Jun 2023, with a remediation deadline of 13 Jul 2023 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution.

References