Aria Operations for Networks contains an arbitrary file write vulnerability. An authenticated malicious actor with administrative access to VMware Aria Operations for Networks can write files to arbitrary locations resulting in remote code execution.
References
Link | Resource |
---|---|
https://www.vmware.com/security/advisories/VMSA-2023-0018.html | Vendor Advisory |
https://www.vmware.com/security/advisories/VMSA-2023-0018.html | Vendor Advisory |
Configurations
History
21 Nov 2024, 07:41
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.vmware.com/security/advisories/VMSA-2023-0018.html - Vendor Advisory |
31 Aug 2023, 18:33
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://www.vmware.com/security/advisories/VMSA-2023-0018.html - Vendor Advisory | |
CPE | cpe:2.3:a:vmware:aria_operations_for_networks:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
First Time |
Vmware aria Operations For Networks
Vmware |
|
CWE | CWE-22 |
29 Aug 2023, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-29 18:15
Updated : 2024-11-21 07:41
NVD link : CVE-2023-20890
Mitre link : CVE-2023-20890
CVE.ORG link : CVE-2023-20890
JSON object : View
Products Affected
vmware
- aria_operations_for_networks
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')