High severity7.2NVD Advisory· Published Feb 22, 2023· Updated Jun 17, 2026
CVE-2023-20858
CVE-2023-20858
Description
VMware Carbon Black App Control 8.7.x prior to 8.7.8, 8.8.x prior to 8.8.6, and 8.9.x.prior to 8.9.4 contain an injection vulnerability. A malicious actor with privileged access to the App Control administration console may be able to use specially crafted input allowing access to the underlying server operating system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- VMware/Carbon Black App Controldescription
<8.7.8, <8.8.6, <8.9.4+ 1 more
- (no CPE)range: <8.7.8, <8.8.6, <8.9.4
- cpe:2.3:a:vmware:carbon_black_app_control:*:*:*:*:*:*:*:*range: >=8.7.0,<8.7.8
Patches
Vulnerability mechanics
References
1- www.vmware.com/security/advisories/VMSA-2023-0004.htmlnvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.