CVE-2023-34039 is a critical authentication bypass vulnerability in VMware Aria Operations for Networks affecting versions 6.0 through 6.10. The flaw stems from non-unique cryptographic key generation for SSH access, resulting in static or reused SSH key material being deployed across installations of affected versions. An attacker with network access to an exposed Aria Operations for Networks system can use the reused keys to authenticate over SSH and access the product CLI without possessing legitimately provisioned credentials. Available technical analysis indicates the issue affected the SSH trust relationship for local service accounts used by the appliance, and vendor remediation regenerated unique keypairs and removed the old authorized keys. Because the vulnerable accounts were reported to have elevated local privileges, successful exploitation could extend beyond CLI access to broader control of the underlying appliance.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module exploit targeting VMware Aria Operations for Networks (vRealize Network Insight) versions 6.0.0 through 6.10.0, affected by CVE-2023-34039. The exploit leverages the fact that these appliances do not randomize SSH private keys on initialization, allowing an attacker to authenticate as the 'support' (root) user using a known private key. The module attempts to connect to the target's SSH service (default port 22) using a set of version-specific private keys, and upon successful authentication, provides an interactive shell to the attacker. The exploit is operational and provides remote command execution as root. The only file in the repository is a Ruby script structured as a Metasploit module, and it references several private key files (not included in this module) for different product versions. The attack vector is network-based, requiring SSH access to the target. No hardcoded IPs or domains are present, but the module expects the operator to specify the target host and port.
This repository provides an operational exploit for CVE-2023-34039, a critical vulnerability in VMWare Aria Operations for Networks (vRealize Network Insight) versions 6.0 through 6.10. The vulnerability arises from the use of static SSH keys for the 'support' (and sometimes 'ubuntu') user accounts, which are not regenerated on installation. The repository contains a single Python script (CVE-2023-34039.py) that automates attempts to authenticate to a target system via SSH using a collection of private keys, each corresponding to a specific product version and component (platform, proxy, collector). The script takes a target IP and optional port, iterates through all provided keys, and attempts to log in as 'support' on the target. If successful, the attacker gains shell access, which can be escalated to root. The repository also includes a comprehensive set of private keys for all affected versions and a README with technical background, usage instructions, and mitigation advice. The attack vector is network-based, requiring SSH access to the target. The exploit is operational, as it provides working keys and a script to automate exploitation, but is not weaponized (no post-exploitation payloads or framework integration).
This repository contains a single Python exploit script (CVE-2023-34039.py) targeting VMWare Aria Operations for Networks (vRealize Network Insight) versions 6.0 to 6.10, exploiting CVE-2023-34039. The exploit leverages static SSH private keys (expected to be present in a local 'keys' directory) to attempt authentication as the 'support' user on the target system via SSH. The script iterates through all key files in the 'keys' directory, attempting to connect to the specified target IP and port. If successful, this can result in remote code execution on the target appliance. The attack vector is network-based, requiring SSH access to the target. The script is operational and requires the attacker to supply the target IP and optionally the SSH port. No payload is delivered beyond gaining SSH access, but this access can be leveraged for further exploitation. The repository is focused and contains only the exploit script.
This repository is a pocsuite3 exploit module targeting VMware vRealize Network Insight (vRNI) versions 6.0.0 through 6.10.0. The main exploit file, 'exp.py', is a Python script that automates SSH login attempts to a target system using a set of hardcoded private SSH keys for the 'support' user, which are included in the 'keys/' directory for each vRNI version. The exploit attempts to authenticate to the target's SSH service (port 22) using each key, providing unauthorized access if the target is vulnerable. The repository contains 23 files: one Python exploit script and 22 private key files, each corresponding to a specific vRNI version and component (platform, proxy, or collector). The exploit is operational, as it provides working keys and a script to automate exploitation, but is not weaponized for mass exploitation. No specific CVE is referenced, but the exploit clearly targets a pre-authentication SSH login bypass in vRNI.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical vulnerability in VMware Aria Operations for Networks caused by hardcoded or non-unique SSH cryptographic keys, allowing an attacker with network access to bypass SSH authentication and gain CLI access, effectively enabling remote access/RCE-like compromise.
Kriittinen haavoittuvuus VMware Aria Operations for Networks -tuotteessa, joka mahdollistaa SSH-todennuksen ohituksen verkon yli ja pääsyn tuotteen käyttöliittymään.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.