CVE-2023-20887
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution.
| Vendor | n/a |
| Product | aria operations for networks (formerly vrealize network insight) |
| Published | Jun 7, 2023 |
| Last Updated | Oct 21, 2025 |
โ ๏ธ Actively Exploited โ Act Now
Get instant alerts for n/a aria operations for networks (formerly vrealize network insight)
This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2023-20887.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
n/a / Aria Operations for Networks (Formerly vRealize Network Insight)
Aria Operations for Networks (Formerly vRealize Network Insight) 6.x
References
vmware.com: https://www.vmware.com/security/advisories/VMSA-2023-0012.html packetstormsecurity.com: http://packetstormsecurity.com/files/173761/VMWare-Aria-Operations-For-Networks-Remote-Command-Execution.html cisa.gov: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-20887