CVE-2023-20887 Leads to RCE in VMware Aria Operations for Networks
ID: 2a1604ff-17c7-5d3d-9318-fb6759d2c21c
STIX ID: report--2a1604ff-17c7-5d3d-9318-fb6759d2c21c
Feed Name: CloudSEK Blog
This report documents CVE-2023-20887, a critical (CVSS 9.8) remote command injection in VMware Aria Operations (vRealize Network Insight) affecting version 6.x and above; it explains how an attacker can inject commands via the createSupportBundle/nodeId parameter, how an nginx rewrite trick (adding a dot in the path) can bypass access restrictions to reach the vulnerable endpoint, notes a public PoC on GitHub, and recommends applying VMware's patch and using the provided YARA network detection rule.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
