Tagvent 2023

The Eighth Day Of Tagsmas (2023): Remote Code Execution in VMWare Aria Operations for Networks (CVE-2023-20887)

CVE
CVE-2023-20887
In CISA Kev
Vulnerability
Remote Code Execution
Description
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution.
Tags

Discovery and Initial Impact

CVE-2023-20887 is a critical remote code execution vulnerability discovered in VMware Aria Operations for Networks (formerly known as vRealize Network Insight) versions 6.2 through 6.10. Aria Operations is a network monitoring and management tool. With a CVSS score of 9.8, this vulnerability allows an unauthenticated remote attacker to execute arbitrary commands as root on servers running vulnerable versions of Aria Operations.

Researchers from Juniper Networks discovered CVE-2023-20887. Their analysis found that improper input validation in a Java server component allowed command injection and that this could enable a remote attacker to achieve unauthorized remote code execution. 

Exploitation and Long-Term Impacts

Within a week of disclosure on June 7, 2023, researchers at GreyNoise observed attempted mass-scanning activity from internet sources utilizing proof-of-concept exploit code that continues today. Since CVE-2023-20887 grants remote code execution, successfully exploited servers could allow threat actors to move laterally and compromise other systems.

Why Defenders Should Still Be Concerned

Ongoing scanning activity indicates that attackers continue to find and compromise any unpatched instances accessible online.

While VMware has released patches, organizations that still need to update remain at risk. They should confirm external firewall rules are not unnecessarily exposing applications, look for signs of compromise across their environment, and apply updates if they find a vulnerable Aria Operations instance.

Related Links

< Back to Tagvent Calendar