CVE-2023-20858
published 2023-02-22CVE-2023-20858: VMware Carbon Black App Control 8.7.x prior to 8.7.8, 8.8.x prior to 8.8.6, and 8.9.x.prior to 8.9.4 contain an injection vulnerability. A malicious actor with…
PriorityP355high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
16.87%
96.7th percentile
VMware Carbon Black App Control 8.7.x prior to 8.7.8, 8.8.x prior to 8.8.6, and 8.9.x.prior to 8.9.4 contain an injection vulnerability. A malicious actor with privileged access to the App Control administration console may be able to use specially crafted input allowing access to the underlying server operating system.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | carbon_black_app_control | >= 8.7.0 < 8.7.8 | 8.7.8 |
| vmware | carbon_black_app_control | >= 8.8.0 < 8.8.6 | 8.8.6 |
| vmware | carbon_black_app_control | >= 8.9.0 < 8.9.4 | 8.9.4 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware Carbon Black App Control updates address an injection vulnerability (CVE-2023-20858)
vendor_vmware·2023-02-21·CVSS 7.2
CVE-2023-20858 [HIGH] VMware Carbon Black App Control updates address an injection vulnerability (CVE-2023-20858)
VMSA-2023-0004: VMware Carbon Black App Control updates address an injection vulnerability (CVE-2023-20858)
VMware Carbon Black App Control contains an injection vulnerability. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.1.
CVEs: CVE-2023-20858
Affected products: VMware Carbon Black
GHSA
GHSA-cfhc-8r7r-vh6v: VMware Carbon Black App Control 8
ghsa_unreviewed·2023-02-22
CVE-2023-20858 [HIGH] CWE-74 GHSA-cfhc-8r7r-vh6v: VMware Carbon Black App Control 8
VMware Carbon Black App Control 8.7.x prior to 8.7.8, 8.8.x prior to 8.8.6, and 8.9.x.prior to 8.9.4 contain an injection vulnerability. A malicious actor with privileged access to the App Control administration console may be able to use specially crafted input allowing access to the underlying server operating system.
No detection rules found.
No public exploits indexed.
2023-02-22
Published