CVE-2023-20858Injection in Vmware Carbon Black APP Control

CWE-74Injection4 documents4 sources
Severity
7.2HIGHNVD
EPSS
4.2%
top 11.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 22

Description

VMware Carbon Black App Control 8.7.x prior to 8.7.8, 8.8.x prior to 8.8.6, and 8.9.x.prior to 8.9.4 contain an injection vulnerability. A malicious actor with privileged access to the App Control administration console may be able to use specially crafted input allowing access to the underlying server operating system.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages1 packages

NVDvmware/carbon_black_app_control8.7.08.7.8+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-cfhc-8r7r-vh6v: VMware Carbon Black App Control 82023-02-22
CVEList
CVE-2023-20858: VMware Carbon Black App Control 82023-02-21

📋Vendor Advisories

1
VMware
VMware Carbon Black App Control updates address an injection vulnerability (CVE-2023-20858)2023-02-21
CVE-2023-20858 — Injection in Vmware | cvebase