Security News > 2023 > June > Urgent Security Updates: Cisco and VMware Address Critical Vulnerabilities

VMware has released security updates to fix a trio of flaws in Aria Operations for Networks that could result in information disclosure and remote code execution.
The most critical of the three vulnerabilities is a command injection vulnerability tracked as CVE-2023-20887 that could allow a malicious actor with network access to achieve remote code execution.
"A malicious actor with network access to VMware Aria Operations for Networks and valid 'member' role credentials may be able to perform a deserialization attack resulting in remote code execution," the company said in an advisory.
The third security defect is a high-severity information disclosure bug that could permit an actor with network access to perform a command injection attack and obtain access to sensitive data.
The alert comes as Cisco shipped fixes for a critical flaw in its Expressway Series and TelePresence Video Communication Server that could "Allow an authenticated attacker with Administrator-level read-only credentials to elevate their privileges to Administrator with read-write credentials on an affected system."
Discover the untapped vulnerabilities in your API ecosystem and take proactive steps towards ironclad security.
News URL
https://thehackernews.com/2023/06/urgent-security-updates-cisco-and.html
Related news
- Ongoing Cyber Attacks Exploit Critical Vulnerabilities in Cisco Smart Licensing Utility (source)
- Still Using an Older Version of iOS or iPadOS? Update Now to Patch These Critical Security Vulnerabilities (source)
- 89% of Enterprise GenAI Usage Is Invisible to Organizations Exposing Critical Security Risks, New Report Reveals (source)
- CISA tags Windows, Cisco vulnerabilities as actively exploited (source)
- Google's March 2025 Android Security Update Fixes Two Actively Exploited Vulnerabilities (source)
- VMware Security Flaws Exploited in the Wild—Broadcom Releases Urgent Patches (source)
- GitLab patches critical authentication bypass vulnerabilities (source)
- Stealthy Apache Tomcat Critical Exploit Bypasses Security Filters: Are You at Risk? (source)
- Critical Cisco Smart Licensing Utility flaws now exploited in attacks (source)
- New Security Flaws Found in VMware Tools and CrushFTP — High Risk, PoC Released (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-06-07 | CVE-2023-20887 | Command Injection vulnerability in VMWare Aria Operations for Networks Aria Operations for Networks contains a command injection vulnerability. | 9.8 |