← All CVEs

CVE-2023-20890

high · 7.2

Aria Operations for Networks contains an arbitrary file write vulnerability. An authenticated malicious actor with administrative access to VMware Aria Operations for Networks can write files to arbitrary locations resulting in remote code execution.

7.2
CVSS
20.2%
EPSS (exploit prob.)
97th
EPSS percentile
2023-08-29
Published

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-22

Affected products

VendorProductAffected versions
vmwarearia_operations_for_networks>= 6.2.0, < 6.11.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-20890