overview
A recently patched critical VMware vulnerability is now being exploited in the wild. CVE-2023-20887 is a command injection vulnerability found in Aria Operations for Networks. The vulnerability allows attackers with network access to launch a command injection attack which results in remote code execution.
CVE-2023-20887 has a CVSS score of 9.8 and impacts VMware Aria Operations for Networks version 6.x. The company has patched the vulnerability and has released fixes in the following versions:
Although VMware has not released information regarding real-world attacks, the company has acknowledged that the vulnerability is being weaponized. The attacks have come after several warnings from the threat intelligence firm GreyNoise. The firm observed attempted mass-scanning activity after a researcher published the Proof-of-Concept code for CVE-2023-20887. According to data collected by GreyNoise, exploitation of the vulnerability originated on June 13, 2023, from two IP addresses located in the Netherlands. Because there are no workarounds, users of Aria Operations for Networks are advised to patch immediately to keep systems and networks secure.
INDICATORS OF COMPROMISE (IoCs)
IP Addresses
SUPPORTING DOCUMENTATION