Multiple Aria Operations Vulnerabilities were reported to Vmware on June 07.
It is also announced that patches for the affected Vmware product remediation are available. According to Vmware; Aria Operations for networks contains command injection vulnerabilities. Therefore a malicious actor with access to the Vmware Aria Operations network may perform a command injection attack wich may lead to remote code execution. (CVE-2023-20887)
Affected Systems
-
IoC’s
-
Recommended Solution(s)
Please apply the updates listed in the 'Fixed Version' column of the 'Response Matrix' on the Vmware Security Advisories webpage for remediation:
https://www.vmware.com/security/advisories/VMSA-2023-0012.htmlMitigations
-
CVE / CWE
CVE-2023-20887
Related Website(s)
* Vulnerabilities with a CVSS 3.1 score between 7.0 and 8.9 are evaluated to be “high” whereas vulnerabilities with a CVSS 3.1 score between 9.0 and 10.0 are evaluated to be “critical”.
+90 216 504 53 32
Aydınevler Mahallesi,İsmet İnönü Cadddesi,Küçükyalı Ofis Park A Blok,No:20/1 Maltepe İstanbul
+90 312 235 44 51
You can register to our newsletter on the home page to be instantly informed about security vulnerabilities.