CVE-2023-20889 is an information disclosure vulnerability in VMware Aria Operations for Networks (formerly vRealize Network Insight). An unauthenticated attacker with network access can exploit this flaw via command injection to gain sensitive information. Rated 7.5 HIGH on CVSS, this vulnerability is easily exploitable with low attack complexity and no user interaction required, leading to high confidentiality impact. While not yet listed on CISA's KEV catalog, its high EPSS score, FAUCET Risk Score, and significant community discussion (including Nuclei templates and media coverage of mass exploitation attempts) indicate a high likelihood of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.2.0, <= 6.10.0CPE matchmatch criteria | cpe:2.3:a:vmware:vrealize_network_insight:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.