CVE-2023-20888 is an authenticated deserialization vulnerability affecting VMware Aria Operations for Networks (formerly vRealize Network Insight). This high-severity flaw (CVSS 8.8) allows an attacker with valid 'member' role credentials and network access to execute arbitrary code remotely. While not listed in CISA KEV, exploit intelligence indicates public Nuclei templates exist, and it has garnered significant community discussion and media coverage, suggesting potential for active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.2.0, <= 6.10.0CPE matchmatch criteria | cpe:2.3:a:vmware:vrealize_network_insight:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.