← Vulnerability feed

Vulnerability record · CVE-2023-20864 · published 20 April 2023

CVE-2023-20864: VMware Aria Operations for Logs deserialization allows unauthenticated root RCE

Vmware · Aria Operations For Logs

VMware Aria Operations for Logs (and Cloud Foundation) contains a deserialization of untrusted data flaw. An unauthenticated attacker with network access can exploit it to run arbitrary code as root. The record does not list specific affected versions; consult the vendor advisory for those.

9.8 CVSS 3.1 Critical EPSS 70% · top 0.6% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityUnauthenticated network-reachable remote code execution as root with a 9.8 CVSS score and very high EPSS probability.

What it is

VMware Aria Operations for Logs (and Cloud Foundation) contains a deserialization of untrusted data flaw. An unauthenticated attacker with network access can exploit it to run arbitrary code as root. The record does not list specific affected versions; consult the vendor advisory for those.

Impact

An attacker gains remote code execution with root privileges on the affected appliance, leading to full compromise of the logging platform and any data or credentials it holds.

Attack surface

Reachable over the network with no authentication and no user interaction required, per the CVSS vector (AV:N/PR:N/UI:N). The description confirms network access to the product is sufficient.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged, but EPSS is very high (0.704, 99.4th percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Apply the fixed version from VMware security advisory VMSA-2023-0007 as the first action.
  • Restrict network access to Aria Operations for Logs management and API interfaces to trusted hosts only.
  • Isolate the appliance on a segmented management network with no direct internet exposure.
  • Monitor vendor advisory for updated affected-version guidance and re-check Cloud Foundation deployments.
  • Rotate credentials and secrets stored or processed by the appliance if compromise is suspected.

Detection

  • Hunt for unexpected outbound connections or child processes spawned by the Aria Operations for Logs service account.
  • Alert on anomalous process creation under the appliance's Java service, especially shells or interpreters.
  • Review appliance and web access logs for unusual POST requests or serialized payload patterns to exposed endpoints.
  • Monitor for new privileged accounts, cron entries, or SSH keys on the appliance host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-20864 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-38813VMware vCenter Server privilege escalation to root via crafted packetvCenter Server contains a privilege escalation flaw where a malicious actor with network access can send a specially crafted network packet to escala…KEVEPSS 17%analysed9.8CVE-2024-38812VMware vCenter Server DCERPC heap overflow allows remote code executionvCenter Server contains a heap-based buffer overflow (CWE-122/CWE-787) in its DCERPC protocol implementation. A remote, unauthenticated attacker can …KEVEPSS 55%analysed9.8CVE-2024-37079VMware vCenter Server DCERPC heap overflow allows remote code executionvCenter Server contains a heap-overflow (out-of-bounds write) in its DCERPC protocol implementation. A remote, unauthenticated attacker can send a cr…KEVEPSS 22%analysed9.8CVE-2022-22954VMware Workspace ONE Access and Identity Manager server-side template injection RCEVMware Workspace ONE Access and Identity Manager are affected by a server-side template injection flaw that allows remote code execution. A network-r…KEVEPSS 100%analysed9.8CVE-2021-22005VMware vCenter Server Analytics arbitrary file upload to RCEThe Analytics service in VMware vCenter Server accepts a specially crafted file upload, which the product mishandles as a path traversal issue (CWE-2…KEVEPSS 100%analysed9.8CVE-2021-21985VMware vCenter Server Virtual SAN Health Check plug-in RCEThe vSphere Client (HTML5) in vCenter Server fails to validate input in the Virtual SAN Health Check plug-in, which is enabled by default. This allow…KEVEPSS 100%analysed9.8CVE-2021-21972VMware vCenter Server plugin path traversal leads to remote code executionThe vSphere Client (HTML5) in vCenter Server contains a path traversal flaw (CWE-22) in a plugin that allows an unauthenticated network attacker to u…KEVEPSS 100%analysed9.8CVE-2020-3992VMware ESXi OpenSLP use-after-free allows remote code executionOpenSLP as used in VMware ESXi contains a use-after-free flaw reachable over port 427 on the management network. An unauthenticated attacker with net…KEVEPSS 83%analysed

Source: NIST National Vulnerability Database (record CVE-2023-20864), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.