Skip to content
Threat Feed
critical advisory

Authentication Bypass and RCE in VMware vRealize Log Insight (CVE-2023-34051)

CVE-2023-34051 is an authentication bypass in VMware vRealize Log Insight that allows unauthenticated arbitrary file write and remote code execution via chained exploitation of Thrift RPC endpoints.

CVE search metadata

CVE search record: CVE-2023-34051. Severity: critical. CVSS: 9.8. EPSS: 44.67%. KEV: no. Product: vRealize Log Insight (<= 8.10.2), Aria Operations for Logs. Brief: Authentication Bypass and RCE in VMware vRealize Log Insight (CVE-2023-34051). Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2023-34051/

CVE search record: CVE-2022-31704. Severity: critical. CVSS: 9.8. EPSS: 81.01%. KEV: no. Product: vRealize Log Insight (<= 8.10.2), Aria Operations for Logs. Brief: Authentication Bypass and RCE in VMware vRealize Log Insight (CVE-2023-34051). Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2023-34051/

CVE search record: CVE-2022-31706. Severity: critical. CVSS: 9.8. EPSS: 87.08%. KEV: no. Product: vRealize Log Insight (<= 8.10.2), Aria Operations for Logs. Brief: Authentication Bypass and RCE in VMware vRealize Log Insight (CVE-2023-34051). Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2023-34051/

CVE search record: CVE-2022-31711. Severity: medium. CVSS: 5.3. EPSS: 21.66%. KEV: no. Product: vRealize Log Insight (<= 8.10.2), Aria Operations for Logs. Brief: Authentication Bypass and RCE in VMware vRealize Log Insight (CVE-2023-34051). Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2023-34051/

CVE-2023-34051 is a high-severity authentication bypass vulnerability affecting VMware vRealize Log Insight (rebranded as VMware Aria Operations for Logs) up to version 8.10.2. This vulnerability acts as a patch bypass for previous security updates associated with VMSA-2023-0001. Attackers can leverage IP address spoofing to interact with internal Thrift RPC endpoints, enabling unauthenticated arbitrary file write capabilities.

By chaining CVE-2023-34051 with existing vulnerabilities (CVE-2022-31704, CVE-2022-31706, and CVE-2022-31711), a remote unauthenticated attacker can achieve full remote code execution (RCE). The exploitation process typically involves leaking node tokens, triggering the download of malicious files, and utilizing directory traversal to write persistent cron jobs, effectively granting the attacker a reverse shell on the target appliance. This threat is critical due to the availability of functional proof-of-concept exploits and the high CVSS score of 9.8.

Attack Chain

  1. Attacker spoofs the IP address of a trusted node within the vRealize Log Insight environment to bypass initial access controls.
  2. Attacker interacts with Thrift RPC endpoints to enumerate service information.
  3. Attacker exploits CVE-2022-31711 to leak a valid node token from the target system.
  4. Attacker uses the leaked token to facilitate further unauthorized requests.
  5. Attacker exploits CVE-2022-31704 to trigger the target system to download a malicious file (e.g., an archive containing a payload) from an attacker-controlled HTTP server.
  6. Attacker leverages CVE-2022-31706 (directory traversal) to move the downloaded file to a sensitive system directory, such as /etc/cron.d/.
  7. The system executes the malicious cron job, resulting in a reverse shell connection back to the attacker.

Impact

Successful exploitation leads to full system compromise, allowing an unauthenticated attacker to execute arbitrary code with root privileges. This impacts the confidentiality, integrity, and availability of the logs managed by the appliance. Organizations running unpatched versions of vRealize Log Insight or VMware Aria Operations for Logs are at extreme risk of total appliance takeover and potential lateral movement into the broader infrastructure.

Recommendation

Prioritize the immediate upgrade of all VMware vRealize Log Insight and Aria Operations for Logs instances to the latest patched versions as specified in VMSA-2023-0021. Review web and network logs for unauthorized access patterns targeting Thrift RPC ports, particularly from IPs matching the organization's internal node address space. Audit the contents of /etc/cron.d/ for unauthorized entries that may indicate post-exploitation persistence.


Immediate actions

Upgrade vRealize Log Insight to the fixed version defined in VMSA-2023-0021

IT Operations 24h

Mitigations

Upgrade VMware Aria Operations for Logs to the version specified in VMSA-2023-0021

immediate IT Operations

CVE-2023-34051