CVE-2023-20890

HIGH

VMware Aria Operations for Networks 6.2.0-6.10.0 - Authenticated Arbitrary File Write and Remote Code Execution

Title source: llm
STIX 2.1

Description

Aria Operations for Networks contains an arbitrary file write vulnerability. An authenticated malicious actor with administrative access to VMware Aria Operations for Networks can write files to arbitrary locations resulting in remote code execution.

References (1)

Core 1

Scores

CVSS v3 7.2
EPSS 0.0081
EPSS Percentile 74.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (1)
vmware/aria_operations_for_networks 6.2.0 - 6.11.0
Published Aug 29, 2023
Tracked Since Feb 18, 2026