Known vulnerabilities in Aria Operations for Networks (formerly vRealize Network Insight) 6.5.1.1

Vendor: Broadcom
Version: 6.5.1.1
Software CPE: cpe:2.3:a:broadcom:vrealize_network_insight:*:*:*:*:*:*:*:*
Total vulnerabilities: 10
Public exploits: 1
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Aria Operations for Networks (formerly vRealize Network Insight) version 6.5.1.1 Aria Operations for Networks (formerly vRealize Network Insight) 6.5.1.1 is affected by 10 vulnerabilities: 2 critical, 1 high, 2 medium, 5 low Critical High Medium Low

Vulnerabilities (10)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU86195 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-22241
CWE-79 Low
No
No
6.12 06.02.2024 SB2024020648
#VU86194 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-22240
CWE-22 Low
No
No
6.12 06.02.2024 SB2024020648
#VU86193 - Permissions, Privileges, and Access Controls
CVE-2024-22239
CWE-264 Low
No
No
6.12 06.02.2024 SB2024020648
#VU86192 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-22238
CWE-79 Low
No
No
6.12 06.02.2024 SB2024020648
#VU86191 - Permissions, Privileges, and Access Controls
CVE-2024-22237
CWE-264 Low
No
No
6.12 06.02.2024 SB2024020648
#VU77078 - Improper Control of Generation of Code ('Code Injection')
CVE-2023-20889
CWE-94 Medium
No
No
- 07.06.2023 SB2023060735
#VU77077 - Deserialization of Untrusted Data
CVE-2023-20888
CWE-502 Medium
No
No
- 07.06.2023 SB2023060735
#VU77076 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-20887
CWE-78 Critical
Public exploit available
Exploited
- 07.06.2023 SB2023060735
#VU70144 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-31703
CWE-22 High
No
No
6.2.7, 6.3.4, 6.4.8, 6.5.1.5, 6.6.4, 6.7.4, 6.8.0 13.12.2022 SB2022121329
#VU70143 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-31702
CWE-78 Critical
No
No
6.2.7, 6.3.4, 6.4.8, 6.5.1.5, 6.6.4, 6.7.4, 6.8.0 13.12.2022 SB2022121329