Record summary

CVE-2023-20889 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Aria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in information disclosure.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 7, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Aria Operations for Networks (Formerly vRealize Network Insight)

Default status: unaffected

CVE ListAria Operations for Networks (Formerly vRealize Network Insight) 6.xaffected

Nuclei templates

1
ProjectDiscoveryHIGHVMware Aria Operations for Networks - Code Injection Information Disclosure VulnerabilityCVSS 7.5

Aria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in information disclosure.

Impact

Successful exploitation of this vulnerability can result in unauthorized access to sensitive information.

Remediation

Apply the latest security patches provided by VMware to mitigate this vulnerability.

WeaknessesCWE-77
Authorsiamnoooob, rootxharsh, pdresearch
Template tagscve2023cvevmwareariadisclosureauthenticatedrceoastintrusivevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:vmware:vrealize_network_insight:*:*:*:*:*:*:*:*
Shodan: title:"VMware Aria Operations"
Shodan: http.title:"vmware vrealize network insight"
Shodan: http.title:"vmware aria operations"
FOFA: title="vmware vrealize network insight"
FOFA: title="vmware aria operations"
Google: intitle:"vmware aria operations"
Google: intitle:"vmware vrealize network insight"

Source: ProjectDiscovery

References

2