google / tsunami-security-scanner-plugins

This project aims to provide a central repository for many useful Tsunami Security Scanner plugins.
Apache License 2.0
860 stars 178 forks source link

Vmware vRealize network insight RCE CVE 2023-20887 #384

Open secureness opened 5 months ago

secureness commented 5 months ago

Related to this issue.

Setup instructions are vast and depend on whether you have a network with an ESXi host, a DNS server, and an NTP server.

installation file(vRealize Network Insight - Platform OVA file): https://customerconnect.vmware.com/en/downloads/details?downloadGroup=VRNI-670&productId=1070&rPId=83873

patch file (VMware Aria Operations for Networks 6.7.0 P5 Patch bundle): https://kb.vmware.com/s/article/92684

secureness commented 1 week ago

@leonardo-doyensec I'm sorry if I should not ping you since this is a really important product I'd like to ask you to check this plugin sooner. it seems that setting up a VCenter in a local computer without any physical server can be interesting and hard :) I already used this complete tutorial to set up a home lab on a VMware workstation: https://www.youtube.com/watch?v=ivTDffsFTHw&list=PLiWivaJb025ZSNxervevLYscEBCkCYuQP

it was a good experience for me, I believe you already know this though.

it would be great if I could get feedback on this ASAP.