OS Command Injection in Aria Operations for Networks (formerly vRealize Network Insight) - CVE-2023-20887
Published: June 7, 2023 / Updated: August 16, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation within the createSupportBundle method. A remote unauthenticated attacker can pass specially crafted data to the application and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
How to mitigate CVE-2023-20887
Links to Public Exploits and PoC-codes
- Exploit #10403 - CVE-2023-20887 (VMWare vRealize Network Insight Pre-Authenticated RCE (CVE-2023-20887)) (August 16, 2024)
- Exploit #10200 - CVE-2023-20887 (VMWare vRealize Network Insight Pre-Authenticated RCE (CVE-2023-20887)) (July 12, 2024)
- Exploit #9202 - VMWare Aria Operations for Networks (vRealize Network Insight) pre-authenticated RCE (July 25, 2023)
- Exploit #9135 - CVE-2023-20887 (VMWare vRealize Network Insight Pre-Authenticated RCE (CVE-2023-20887)) (June 26, 2023)