{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/aria-operations-for-logs/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:vmware:vrealize_log_insight:*:*:*:*:*:*:*:*","cpe:2.3:a:vmware:aria_operations_for_logs:4.0:*:*:*:*:*:*:*","cpe:2.3:a:vmware:aria_operations_for_logs:5.0:*:*:*:*:*:*:*","cpe:2.3:a:vmware:aria_operations_for_logs:8.6:*:*:*:*:*:*:*","cpe:2.3:a:vmware:aria_operations_for_logs:8.8:*:*:*:*:*:*:*","cpe:2.3:a:vmware:aria_operations_for_logs:8.10:*:*:*:*:*:*:*","cpe:2.3:a:vmware:aria_operations_for_logs:8.10.2:*:*:*:*:*:*:*","cpe:2.3:a:vmware:aria_operations_for_logs:8.12:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2023-34051"},{"cvss":9.8,"id":"CVE-2022-31704"},{"cvss":9.8,"id":"CVE-2022-31706"},{"cvss":5.3,"id":"CVE-2022-31711"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["vRealize Log Insight (\u003c= 8.10.2)","Aria Operations for Logs"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","remote-code-execution","cve"],"_cs_type":"advisory","_cs_vendors":["VMware"],"content_html":"\u003cp\u003eCVE-2023-34051 is a high-severity authentication bypass vulnerability affecting VMware vRealize Log Insight (rebranded as VMware Aria Operations for Logs) up to version 8.10.2. This vulnerability acts as a patch bypass for previous security updates associated with VMSA-2023-0001. Attackers can leverage IP address spoofing to interact with internal Thrift RPC endpoints, enabling unauthenticated arbitrary file write capabilities.\u003c/p\u003e\n\u003cp\u003eBy chaining CVE-2023-34051 with existing vulnerabilities (CVE-2022-31704, CVE-2022-31706, and CVE-2022-31711), a remote unauthenticated attacker can achieve full remote code execution (RCE). The exploitation process typically involves leaking node tokens, triggering the download of malicious files, and utilizing directory traversal to write persistent cron jobs, effectively granting the attacker a reverse shell on the target appliance. This threat is critical due to the availability of functional proof-of-concept exploits and the high CVSS score of 9.8.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker spoofs the IP address of a trusted node within the vRealize Log Insight environment to bypass initial access controls.\u003c/li\u003e\n\u003cli\u003eAttacker interacts with Thrift RPC endpoints to enumerate service information.\u003c/li\u003e\n\u003cli\u003eAttacker exploits CVE-2022-31711 to leak a valid node token from the target system.\u003c/li\u003e\n\u003cli\u003eAttacker uses the leaked token to facilitate further unauthorized requests.\u003c/li\u003e\n\u003cli\u003eAttacker exploits CVE-2022-31704 to trigger the target system to download a malicious file (e.g., an archive containing a payload) from an attacker-controlled HTTP server.\u003c/li\u003e\n\u003cli\u003eAttacker leverages CVE-2022-31706 (directory traversal) to move the downloaded file to a sensitive system directory, such as /etc/cron.d/.\u003c/li\u003e\n\u003cli\u003eThe system executes the malicious cron job, resulting in a reverse shell connection back to the attacker.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to full system compromise, allowing an unauthenticated attacker to execute arbitrary code with root privileges. This impacts the confidentiality, integrity, and availability of the logs managed by the appliance. Organizations running unpatched versions of vRealize Log Insight or VMware Aria Operations for Logs are at extreme risk of total appliance takeover and potential lateral movement into the broader infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate upgrade of all VMware vRealize Log Insight and Aria Operations for Logs instances to the latest patched versions as specified in VMSA-2023-0021. Review web and network logs for unauthorized access patterns targeting Thrift RPC ports, particularly from IPs matching the organization's internal node address space. Audit the contents of /etc/cron.d/ for unauthorized entries that may indicate post-exploitation persistence.\u003c/p\u003e\n","date_modified":"2026-09-05T01:15:43Z","date_published":"2026-09-05T01:15:43Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2023-34051/","summary":"CVE-2023-34051 is an authentication bypass in VMware vRealize Log Insight that allows unauthenticated arbitrary file write and remote code execution via chained exploitation of Thrift RPC endpoints.","title":"Authentication Bypass and RCE in VMware vRealize Log Insight (CVE-2023-34051)","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2023-34051/"}],"language":"en","title":"CraftedSignal Threat Feed - Aria Operations for Logs","version":"https://jsonfeed.org/version/1.1"}