Lucene search

K
vmwareVMwareVMSA-2023-0012.1
HistoryJun 07, 2023 - 12:00 a.m.

VMware Aria Operations for Networks updates address multiple vulnerabilities. (CVE-2023-20887, CVE-2023-20888, CVE-2023-20889)

2023-06-0700:00:00
www.vmware.com
23
vmware
aria operations
networks
command injection
authenticated deserialization
information disclosure
vulnerability
cve-2023-20887
cve-2023-20888
cve-2023-20889
critical severity
cvssv3

EPSS

0.971

Percentile

99.8%

3a. Aria Operations for Networks Command Injection Vulnerability (CVE-2023-20887)

Aria Operations for Networks contains a command injection vulnerability. VMware has evaluated the severity of this issue to be in the critical severity range with a maximum CVSSv3 base score of 9.8.

3b. Aria Operations for Networks Authenticated Deserialization Vulnerability (CVE-2023-20888)

Aria Operations for Networks contains an authenticated deserialization vulnerability. VMware has evaluated the severity of this issue to be in the critical severity range with a maximum CVSSv3 base score of 9.1.

3c. Aria Operations for Networks Information Disclosure Vulnerability (CVE-2023-20889)

Aria Operations for Networks contains an information disclosure vulnerability. VMware has evaluated the severity of this issue to be in the important severity range with a maximum CVSSv3 base score of 8.8.