CVE-2023-20887 is a critical command injection vulnerability affecting VMware Aria Operations for Networks, formerly VMware vRealize Network Insight. The issue is exploitable pre-authentication and can lead to remote code execution. Available technical reporting describes the vulnerability as a chain of two flaws: an nginx path restriction bypass that exposes an internal Apache Thrift RPC endpoint, and a command injection condition in the support bundle creation workflow. The exposed RestToSaasCommunication Thrift service includes a createSupportBundle procedure that accepts attacker-controlled input, including nodeId. That value is passed into support bundle cleanup logic in ScriptUtils.evictPublishedSupportBundles, where it is incorporated into shell command construction and executed, enabling arbitrary command injection. An external attacker can reach the otherwise restricted internal servlet by using a crafted request path that bypasses the localhost-only nginx rule and is rewritten and proxied to the Thrift backend.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module targeting CVE-2023-20887, a critical pre-authenticated remote command execution vulnerability in VMware Aria Operations for Networks (vRealize Network Insight) versions 6.2 to 6.10. The exploit leverages a command injection flaw in the Apache Thrift RPC interface, accessible via a reverse proxy, to execute arbitrary commands as root on the target appliance. The module supports both in-memory command execution and a Linux dropper using command stagers (curl, printf), and can deliver a Meterpreter reverse shell or other payloads. The main endpoints targeted are '/api/vip/i18n/api/v2/translation/products/vRNIUI/versions/6.x.0/locales/en-GB/components/UI' (for version detection) and '/saas./resttosaasservlet' (for exploitation). The code is written in Ruby and is fully integrated into the Metasploit framework, making it weaponized and highly customizable for offensive operations.
This repository contains multiple exploit implementations for CVE-2023-20887, a critical unauthenticated remote code execution vulnerability in VMware Aria Operations for Networks (vRealize Network Insight) 6.x. The vulnerability allows attackers to execute arbitrary commands as root via the Apache Thrift RPC interface, specifically targeting the '/saas./resttosaasservlet' endpoint. The repository includes: - A Python exploit script (CVE-2023-20887.py) that sets up a reverse shell handler and sends a crafted payload to the vulnerable endpoint, resulting in a root shell on the target. - A Metasploit module (vmware_vrni_rce_cve_2023_20887.rb) that weaponizes the exploit, supporting various payloads (reverse shell, Meterpreter) and automating detection and exploitation. - A Nuclei template (nuclei-CVE-2023-20887.yaml) for automated vulnerability scanning and detection. - A README.md with technical analysis, usage instructions, and mitigation advice. The main attack vector is network-based, requiring only access to the target's HTTP(S) interface. The exploit is highly weaponized, with both standalone and framework-based (Metasploit) implementations, and can be used for both detection and full exploitation. The endpoints '/saas./resttosaasservlet' (for exploitation) and '/api/vip/i18n/api/v2/translation/products/vRNIUI/versions/6.8.0/locales/en-GB/components/UI?pseudo=false' (for product/version check) are fingerprintable. The repository is well-structured for both offensive and defensive security research.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named VMware Aria Operations / vRealize vulnerability referenced as an associated analytic story, without further detail in the content.
A remote code execution vulnerability affecting VMware vRealize Network Insight / VMware Aria Operations for Networks, where exploitation attempts target the /saas./resttosaasservlet endpoint and could allow arbitrary code execution.
A pre-authentication remote code execution vulnerability chain in VMware Aria Operations for Networks (formerly vRealize Network Insight) involving an nginx access-control bypass to reach an internal Thrift endpoint and a command injection in support bundle handling.
Remote command execution vulnerability in VMware Aria Operations for Networks (mentioned only in a related-stories section).
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.