QID 730825

Date Published: 2023-06-14

QID 730825: VMware Aria Operations for Networks Multiple Security Vulnerabilities (VMSA-2023-0012.1)

VMWare has patched CVE-2023-20887, CVE-2023-20888 and CVE-2023-20889 in its product VMware Aria Operations for Networks, which is formerly known as vRealize Network Insight.

Affected Versions:
VMware Aria Operations for Networks 6.x versions: 6.2, 6.3, 6.4, 6.5.1, 6.6, 6.7, 6.8, 6.9, and 6.10.

QID Detection Logic(Unauthenticated):
This QID checks for vulnerable VMware Aria Operations for Networks target by sending a crafted payload to the webserver. A vulnerable server will try to connect back to the scanner on a random port.

Successful exploitation of the vulnerability may lead an attacker to execute code remotely leading to complete system compromise.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to refer to the vendor advisory VMSA-2023-0012 for more information related to these vulnerabilities.

    CVEs related to QID 730825

    Software Advisories
    Advisory ID Software Component Link
    VMSA-2023-0012.1 URL Logo www.vmware.com/security/advisories/VMSA-2023-0012.html