<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:vmware:aria_operations_for_logs:4.0:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3avmwarearia_operations_for_logs4.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 05 Sep 2026 01:15:43 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3avmwarearia_operations_for_logs4.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass and RCE in VMware vRealize Log Insight (CVE-2023-34051)</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2023-34051/</link><pubDate>Sat, 05 Sep 2026 01:15:43 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2023-34051/</guid><description>CVE-2023-34051 is an authentication bypass in VMware vRealize Log Insight that allows unauthenticated arbitrary file write and remote code execution via chained exploitation of Thrift RPC endpoints.</description><content:encoded><![CDATA[<p>CVE-2023-34051 is a high-severity authentication bypass vulnerability affecting VMware vRealize Log Insight (rebranded as VMware Aria Operations for Logs) up to version 8.10.2. This vulnerability acts as a patch bypass for previous security updates associated with VMSA-2023-0001. Attackers can leverage IP address spoofing to interact with internal Thrift RPC endpoints, enabling unauthenticated arbitrary file write capabilities.</p>
<p>By chaining CVE-2023-34051 with existing vulnerabilities (CVE-2022-31704, CVE-2022-31706, and CVE-2022-31711), a remote unauthenticated attacker can achieve full remote code execution (RCE). The exploitation process typically involves leaking node tokens, triggering the download of malicious files, and utilizing directory traversal to write persistent cron jobs, effectively granting the attacker a reverse shell on the target appliance. This threat is critical due to the availability of functional proof-of-concept exploits and the high CVSS score of 9.8.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker spoofs the IP address of a trusted node within the vRealize Log Insight environment to bypass initial access controls.</li>
<li>Attacker interacts with Thrift RPC endpoints to enumerate service information.</li>
<li>Attacker exploits CVE-2022-31711 to leak a valid node token from the target system.</li>
<li>Attacker uses the leaked token to facilitate further unauthorized requests.</li>
<li>Attacker exploits CVE-2022-31704 to trigger the target system to download a malicious file (e.g., an archive containing a payload) from an attacker-controlled HTTP server.</li>
<li>Attacker leverages CVE-2022-31706 (directory traversal) to move the downloaded file to a sensitive system directory, such as /etc/cron.d/.</li>
<li>The system executes the malicious cron job, resulting in a reverse shell connection back to the attacker.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation leads to full system compromise, allowing an unauthenticated attacker to execute arbitrary code with root privileges. This impacts the confidentiality, integrity, and availability of the logs managed by the appliance. Organizations running unpatched versions of vRealize Log Insight or VMware Aria Operations for Logs are at extreme risk of total appliance takeover and potential lateral movement into the broader infrastructure.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the immediate upgrade of all VMware vRealize Log Insight and Aria Operations for Logs instances to the latest patched versions as specified in VMSA-2023-0021. Review web and network logs for unauthorized access patterns targeting Thrift RPC ports, particularly from IPs matching the organization's internal node address space. Audit the contents of /etc/cron.d/ for unauthorized entries that may indicate post-exploitation persistence.</p>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>vulnerability</category><category>remote-code-execution</category><category>cve</category></item></channel></rss>