PT-2022-6646 · Vmware · Vmware Aria Operations For Networks

Sinsinology

·

Published

2022-11-01

·

Updated

2025-01-07

·

CVE-2023-20888

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions VMware Aria Operations for Networks (affected versions not specified)
Description The issue is related to a deserialization vulnerability in VMware Aria Operations for Networks. This vulnerability can be exploited by a remote attacker to execute arbitrary code. A malicious actor with network access to the system and valid 'member' role credentials may be able to perform a deserialization attack, resulting in remote code execution. The vulnerability is related to the deserialization of untrusted data, specifically in the getNotifiedEvents function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2023-03112
CVE-2023-20888
ZDI-23-841

Affected Products

Vmware Aria Operations For Networks