ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

VMware Aria Operations for Networks vulnerability exploited in the wild (CVE-2023-20887)

criticalExploit / PoC exploited in the wildimportance 60CVE-2023-20887CVE-2023-20888CVE-2023-20889

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-20887
Unauthenticated Command Injection RCE in VMware Aria Operations for Networks

VMware Aria Operations for Networks (formerly vRealize Network Insight) contains a command injection flaw (CWE-77) that allows an attacker with network access to the appliance to run arbitrary operating-system commands. Because the attack requires no authentication, privileges, or user interaction (CVSS:3.1/AV:N/AC:L/PR:N/UI:N), any party able to reach the product's network interface can trigger it, gaining remote code execution with high impact on confidentiality, integrity, and availability. Any organization running the product is affected, with internet-facing deployments at the greatest risk. Exploitation is confirmed in the wild — CISA added the flaw to the KEV catalog on 2023-06-22, a public proof-of-concept exploit is available, and EPSS puts the 30-day exploitation probability at 98.3% (top percentile). Ransomware use is currently unknown.

Do: Apply the vendor's patched update to all Aria Operations for Networks deployments as soon as possible — this is also CISA's required KEV action (apply updates per vendor instructions); verify the installed build against VMware's advisory for affected ranges. Until patching is complete, restrict network access to the appliance (firewall rules, VPN, or management-segment isolation), prioritizing any instance reachable from the internet since no authentication is required to exploit. Hunt for indicators of command injection exploitation, as in-the-wild exploitation has been confirmed.

9.898% KEV PoC
  • VMware Aria Operations for Networks (formerly vRealize Network Insight)
moderate≈10,000+ appliance deployments worldwide (low tens of thousands of appliance nodes); only a small fraction, likely hundreds to low thousands of instances, are…
CVE-2023-20888
+1 in the same advisory: …20889
Aria Operations for Networks contains an authenticated deserialization vulnerability.

Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations for Networks and valid 'member' role credentials may be able to perform a deserialization attack resulting in remote code execution.

NVD description · AI analysis pending
8.8
group max
82%
  • vmware vrealize network insight
Full article194 words · extracted from helpnetsecurity.com · click to collapse

CVE-2023-20887, a pre-authentication command injection vulnerability in VMware Aria Operations for Networks (formerly vRealize Network Insight), has been spotted being exploited in the wild.

There are no workarounds to mitigate the risk of exploitation – enterprise admins are advised to upgrade their deployments with patches.

CVE-2023-20887 exploited

CVE-2023-20887 is one of three vulnerabilities recently discovered by Sina Kheirkhah of Summoning Team and an anonymous researcher and privately reported to VMware.

“A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution,” the company confirmed.

A PoC exploit for CVE-2023-20887 has been published by Kheirkhah on June 13 and, according to GreyNoise, attempts to exploit the flaw started two days after.

“We have observed attempted mass-scanning activity utilizing the Proof-Of-Concept code mentioned above in an attempt to launch a reverse shell which connects back to an attacker controlled server in order to receive further commands,” GreyNoise research analyst Jacob Fisher noted.

CVE-2023-20887, CVE-2023-20888 (an authenticated deserialization vulnerability) and CVE-2023-20889 (an information disclosure vulnerability) affect versions 6.x of the solution. Patches for each version are available here.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/06/21/cve-2023-20887-exploited/