← Vulnerability feed

Vulnerability record · CVE-2023-20887 · published 7 June 2023

CVE-2023-20887: VMware Aria Operations for Networks command injection

Vmware · Aria Operations For Networks

VMware Aria Operations for Networks contains a command injection flaw (CWE-77) that lets a remote attacker execute arbitrary commands on the appliance. It is network-reachable and requires no authentication or user interaction, making it a severe pre-auth RCE risk for exposed deployments.

9.8 CVSS 3.1 Critical CISA KEV since 22 Jun 2023 EPSS 98% · top 0.1% CWE-77 · Command injection
9.8CVSS 3.1 base score
98%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityPre-auth network RCE with CVSS 9.8, KEV listing and near-maximum EPSS probability makes this an urgent patch target.

What it is

VMware Aria Operations for Networks contains a command injection flaw (CWE-77) that lets a remote attacker execute arbitrary commands on the appliance. It is network-reachable and requires no authentication or user interaction, making it a severe pre-auth RCE risk for exposed deployments.

Impact

An attacker gains remote code execution on the Aria Operations for Networks appliance, which can lead to full compromise of the system and any data or credentials it holds.

Attack surface

Reached over the network via the product's exposed interface, per the CVSS vector AV:N/PR:N/UI:N. No authentication or user interaction is required.

Exploitation

Listed in CISA KEV since 2023-06-22 with a required action to apply vendor updates, and EPSS 30-day probability is 0.98281 (percentile 0.99913). Public exploit code is referenced by a Packet Storm advisory tagged Exploit.

What to do

  • Apply the vendor patch per VMware advisory VMSA-2023-0012.
  • Restrict network access to Aria Operations for Networks management interfaces to trusted hosts only.
  • Place the appliance behind a firewall or VPN and remove any direct internet exposure.
  • Monitor for and investigate signs of compromise on unpatched appliances, treating them as potentially breached.
  • Verify patching against CISA KEV remediation guidance and track completion.

Detection

  • Hunt for unexpected child processes spawned by the Aria Operations for Networks web/appliance services.
  • Review appliance and web logs for command injection patterns or anomalous request parameters.
  • Monitor for outbound connections or new listening services on the appliance that are not part of normal operation.
  • Alert on authentication-free access attempts to the management interface from untrusted networks.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-20887 to the Known Exploited Vulnerabilities catalog on 22 June 2023 as "Vmware Aria Operations for Networks Command Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 13 July 2023.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-20887 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-34039VMware Aria Operations for Networks SSH authentication bypassAria Operations for Networks generates non-unique cryptographic keys, allowing SSH authentication to be bypassed. An attacker with network reachabili…EPSS 67%analysed7.8CVE-2024-22237Vmware aria operations for networks improper privilege management vulnerabilityAria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may expl…EPSS 0.25%7.8CVE-2024-22239Vmware aria operations for networks improper privilege management vulnerabilityAria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may expl…EPSS 0.21%7.2CVE-2023-20890Vmware aria operations for networks path traversal vulnerabilityAria Operations for Networks contains an arbitrary file write vulnerability. An authenticated malicious actor with administrative access to VMware Ar…EPSS 20%4.9CVE-2024-22240Vmware aria operations for networks vulnerabilityAria Operations for Networks contains a local file read vulnerability. A malicious actor with admin privileges may exploit this vulnerability leading…EPSS 0.62%4.8CVE-2024-22241Vmware aria operations for networks cross-site scripting vulnerabilityAria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges can inject a malicious payload in…EPSS 38%4.8CVE-2024-22238Vmware aria operations for networks cross-site scripting vulnerabilityAria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges may be able to inject malicious c…EPSS 0.50%9.8CVE-2026-8037Progress LoadMaster API OS Command Injection RCEProgress LoadMaster (and related ADC products) contain an OS command injection flaw in multiple API command endpoints where unsanitized input is pass…KEVEPSS 77%analysed

Source: NIST National Vulnerability Database (record CVE-2023-20887), CISA KEV, FIRST EPSS (scores of 2026-09-18). This page is refreshed as NVD updates the record.