.. / CVE-2023-20889

Exploit for VMware Aria Operations for Networks - Code Injection Information Disclosure Vulnerability (CVE-2023-20889)

Description:

Aria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in information disclosure.

Nuclei Template

View the template here CVE-2023-20889.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2023/CVE-2023-20889.yaml
Copy

References:

https://www.zerodayinitiative.com/advisories/ZDI-23-842/
https://www.vmware.com/security/advisories/VMSA-2023-0012.html
https://nvd.nist.gov/vuln/detail/CVE-2023-20889