๐Ÿ” CVE Alert

CVE-2023-20887

CRITICAL 9.8 โš ๏ธ CISA KEV
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution.

Vendor n/a
Product aria operations for networks (formerly vrealize network insight)
Published Jun 7, 2023
Last Updated Oct 21, 2025
โš ๏ธ Actively Exploited โ€” Act Now

Get instant alerts for n/a aria operations for networks (formerly vrealize network insight)

This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2023-20887.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

n/a / Aria Operations for Networks (Formerly vRealize Network Insight)
Aria Operations for Networks (Formerly vRealize Network Insight) 6.x

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vmware.com: https://www.vmware.com/security/advisories/VMSA-2023-0012.html packetstormsecurity.com: http://packetstormsecurity.com/files/173761/VMWare-Aria-Operations-For-Networks-Remote-Command-Execution.html cisa.gov: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-20887