Security News > 2023 > June > VMware Aria Operations for Networks vulnerability exploited in the wild (CVE-2023-20887)

VMware Aria Operations for Networks vulnerability exploited in the wild (CVE-2023-20887)
2023-06-21 08:25

CVE-2023-20887, a pre-authentication command injection vulnerability in VMware Aria Operations for Networks, has been spotted being exploited in the wild.

CVE-2023-20887 is one of three vulnerabilities recently discovered by Sina Kheirkhah of Summoning Team and an anonymous researcher and privately reported to VMware.

"A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution," the company confirmed.

A PoC exploit for CVE-2023-20887 has been published by Kheirkhah on June 13 and, according to GreyNoise, attempts to exploit the flaw started two days after.

"We have observed attempted mass-scanning activity utilizing the Proof-Of-Concept code mentioned above in an attempt to launch a reverse shell which connects back to an attacker controlled server in order to receive further commands," GreyNoise research analyst Jacob Fisher noted.

CVE-2023-20887, CVE-2023-20888 and CVE-2023-20889 affect versions 6.x of the solution.


News URL

https://www.helpnetsecurity.com/2023/06/21/cve-2023-20887-exploited/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2023-06-07 CVE-2023-20889 Command Injection vulnerability in VMWare Vrealize Network Insight
Aria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in information disclosure.
network
low complexity
vmware CWE-77
7.5
2023-06-07 CVE-2023-20888 Deserialization of Untrusted Data vulnerability in VMWare Vrealize Network Insight
Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations for Networks and valid 'member' role credentials may be able to perform a deserialization attack resulting in remote code execution.
network
low complexity
vmware CWE-502
8.8
2023-06-07 CVE-2023-20887 Command Injection vulnerability in VMWare Aria Operations for Networks
Aria Operations for Networks contains a command injection vulnerability.
network
low complexity
vmware CWE-77
critical
9.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Vmware 146 11 222 256 102 591