Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution.
Loading...
Loading...
Score elevated to 9.8 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2023-06-22), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 9.8 retained for reference. Confidence: HIGH.
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution.
June 7, 2023
October 28, 2025
Known Exploited Vulnerabilities Catalog | CISA. Listed in CISA Known Exploited Vulnerabilities catalog.
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-20887MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
Working exploit code is in the public domain (1 Metasploit module) (3 GitHub PoCs). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
VMWare vRealize Network Insight Pre-Authenticated RCE (CVE-2023-20887)
Open source ↗VMWare vRealize Network Insight Pre-Authenticated RCE (CVE-2023-20887)
Open source ↗VMWare vRealize Network Insight Pre-Authenticated RCE (CVE-2023-20887)
Open source ↗VMWare Aria Operations for Networks (vRealize Network Insight) pre-authenticated RCE
Open source ↗VMware VRealize Network Insight - Remote Code Execution
Open source ↗See which npm, PyPI, Go, and Maven packages are affected by CVE-2023-20887
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.
CWE-77