{"api_version":"1","generated_at":"2026-07-24T18:53:56+00:00","cve":"CVE-2023-20890","urls":{"html":"https://cve.report/CVE-2023-20890","api":"https://cve.report/api/cve/CVE-2023-20890.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-20890","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-20890"},"summary":{"title":"CVE-2023-20890","description":"Aria Operations for Networks contains an arbitrary file write vulnerability. An authenticated malicious actor with administrative access to VMware Aria Operations for Networks can write files to arbitrary locations resulting in remote code execution.","state":"PUBLIC","assigner":"security@vmware.com","published_at":"2023-08-29 18:15:00","updated_at":"2023-08-31 18:33:00"},"problem_types":["CWE-22"],"metrics":[],"references":[{"url":"https://www.vmware.com/security/advisories/VMSA-2023-0018.html","name":"https://www.vmware.com/security/advisories/VMSA-2023-0018.html","refsource":"MISC","tags":[],"title":"VMSA-2023-0018","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-20890","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-20890","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"20890","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"vmware","cpe5":"aria_operations_for_networks","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-20890","ASSIGNER":"security@vmware.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"Aria Operations for Networks contains an arbitrary file write vulnerability. An authenticated malicious actor with administrative access to VMware Aria Operations for Networks can write files to arbitrary locations resulting in remote code execution."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Arbitrary File Write Vulnerability"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"Aria Operations for Networks","version":{"version_data":[{"version_affected":"=","version_value":"Aria Operations for Networks 6.x"}]}}]}}]}},"references":{"reference_data":[{"url":"https://www.vmware.com/security/advisories/VMSA-2023-0018.html","refsource":"MISC","name":"https://www.vmware.com/security/advisories/VMSA-2023-0018.html"}]},"generator":{"engine":"Vulnogram 0.1.0-dev"},"source":{"discovery":"UNKNOWN"},"impact":{"cvss":[{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}]}},"nvd":{"publishedDate":"2023-08-29 18:15:00","lastModifiedDate":"2023-08-31 18:33:00","problem_types":["CWE-22"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:vmware:aria_operations_for_networks:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2.0","versionEndExcluding":"6.11.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}