CVE-2023-20864

CRITICAL NUCLEI

VMware Aria Operations for Logs 8.10.2-8.11.x - Unauthenticated Remote Code Execution via Deserialization

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2023-20864 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.

Nuclei Templates (1)

VMware Aria Operations for Logs - Unauthenticated Remote Code Execution
CRITICALVERIFIEDby rootxharsh,iamnoooob,pdresearch
Shodan: title:"vRealize Log Insight" || http.title:"vrealize log insight"
FOFA: title="vrealize log insight"

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.9298
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-502
Status published
Products (2)
vmware/aria_operations_for_logs 8.10.2 - 8.12.0
vmware/cloud_foundation 4.0 - 4.5
Published Apr 20, 2023
Tracked Since Feb 18, 2026