vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. A malicious actor with network access to the vRNI REST API can execute commands without authentication.
https://www.tenable.com/blog/cve-2023-20887-vmware-aria-operations-for-networks-command-injection
https://www.vmware.com/security/advisories/VMSA-2022-0031.html