.. / CVE-2023-20888

Exploit for VMware Aria Operations for Networks - Remote Code Execution (CVE-2023-20888)

Description:

Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations for Networks and valid ‘member’ role credentials may be able to perform a deserialization attack resulting in remote code execution.

Nuclei Template

View the template here CVE-2023-20888.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2023/CVE-2023-20888.yaml
Copy

References:

https://www.vmware.com/security/advisories/VMSA-2023-0012.html
https://nvd.nist.gov/vuln/detail/CVE-2023-20888