Vulnerability record · CVE-2023-20864 · published 20 April 2023
CVE-2023-20864: VMware Aria Operations for Logs deserialization allows unauthenticated root RCE
Vmware · Aria Operations For Logs
VMware Aria Operations for Logs (and Cloud Foundation) contains a deserialization of untrusted data flaw. An unauthenticated attacker with network access can exploit it to run arbitrary code as root. The record does not list specific affected versions; consult the vendor advisory for those.
Description
VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution as root with a 9.8 CVSS score and very high EPSS probability.
What it is
VMware Aria Operations for Logs (and Cloud Foundation) contains a deserialization of untrusted data flaw. An unauthenticated attacker with network access can exploit it to run arbitrary code as root. The record does not list specific affected versions; consult the vendor advisory for those.
Impact
An attacker gains remote code execution with root privileges on the affected appliance, leading to full compromise of the logging platform and any data or credentials it holds.
Attack surface
Reachable over the network with no authentication and no user interaction required, per the CVSS vector (AV:N/PR:N/UI:N). The description confirms network access to the product is sufficient.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged, but EPSS is very high (0.704, 99.4th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Apply the fixed version from VMware security advisory VMSA-2023-0007 as the first action.
- Restrict network access to Aria Operations for Logs management and API interfaces to trusted hosts only.
- Isolate the appliance on a segmented management network with no direct internet exposure.
- Monitor vendor advisory for updated affected-version guidance and re-check Cloud Foundation deployments.
- Rotate credentials and secrets stored or processed by the appliance if compromise is suspected.
Detection
- Hunt for unexpected outbound connections or child processes spawned by the Aria Operations for Logs service account.
- Alert on anomalous process creation under the appliance's Java service, especially shells or interpreters.
- Review appliance and web access logs for unusual POST requests or serialized payload patterns to exposed endpoints.
- Monitor for new privileged accounts, cron entries, or SSH keys on the appliance host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.vmware.com/security/advisories/VMSA-2023-0007.html | Vendor Advisory |
| https://www.vmware.com/security/advisories/VMSA-2023-0007.html | Vendor Advisory |
Track CVE-2023-20864 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-20864), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.