Lucene search

K
nvd[email protected]NVD:CVE-2023-20888
HistoryJun 07, 2023 - 3:15 p.m.

CVE-2023-20888

2023-06-0715:15:09
CWE-502
web.nvd.nist.gov
7
cve-2023-20888
vmware
deserialization vulnerability
remote code execution

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

9

Confidence

High

EPSS

0.248

Percentile

96.7%

Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations for Networks and valid ‘member’ role credentials may be able to perform a deserialization attack resulting in remote code execution.

Affected configurations

Nvd
Node
vmwarevrealize_network_insightRange6.2.06.10.0
VendorProductVersionCPE
vmwarevrealize_network_insight*cpe:2.3:a:vmware:vrealize_network_insight:*:*:*:*:*:*:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

9

Confidence

High

EPSS

0.248

Percentile

96.7%