CVE Published: 29/08/2023 |
CVE Updated: 01/10/2024 |
CVE Year: 2023 Source: vmware |
Vendor: n/a |
Product: Aria Operations for Networks Status : PUBLISHED
CVE-2023-20890 Description
Aria Operations for Networks contains an arbitrary file write vulnerability. An authenticated malicious actor with administrative access to VMware Aria Operations for Networks can write files to arbitrary locations resulting in remote code execution.
Metrics
CVSS Version: 3.1 |
Base Score: 7.2 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H