CVE-2023-20890: VMware Aria Operations for Networks
High severity, CVSS 7.2. EPSS: 20.2% chance of exploitation in the next 30 days.
Aria Operations for Networks contains an arbitrary file write vulnerability. An authenticated malicious actor with administrative access to VMware Aria Operations for Networks can write files to arbitrary locations resulting in remote code execution.
Affected products
- VMware Aria Operations for Networks: from 6.2.0, before 6.11.0 (fixed in 6.11.0)
Published 2023-08-29. Last modified 2026-06-17.