logo

CVE-2023-20887 Leads to RCE in VMware Aria Operations for Networks

ID: 2a1604ff-17c7-5d3d-9318-fb6759d2c21c

STIX ID: report--2a1604ff-17c7-5d3d-9318-fb6759d2c21c

Feed Name: CloudSEK Blog

Threat Score
85/100

Date Published: 2023-06-16

Date Updated: 2026-04-27

...
...

This report documents CVE-2023-20887, a critical (CVSS 9.8) remote command injection in VMware Aria Operations (vRealize Network Insight) affecting version 6.x and above; it explains how an attacker can inject commands via the createSupportBundle/nodeId parameter, how an nginx rewrite trick (adding a dot in the path) can bypass access restrictions to reach the vulnerable endpoint, notes a public PoC on GitHub, and recommends applying VMware's patch and using the provided YARA network detection rule.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.