-
Notifications
You must be signed in to change notification settings - Fork 180
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
PRP: Vmware VRealize network insight RCE CVE 2023-20887 #331
Comments
Hi @secureness, based on the article you linked this vuln is in scope for Tsunami. Do you know if there's an easy way to spin up this service locally, so that I can test out the plugin during the code review? |
Hi @maoning |
Hi @maoning |
Hi @secureness, Thank you for following up on the details of testing the vulnerable vCenter instance. I think we are good to move on the development & review phase. Please share the detailed instructions of how to set up everything in your merge request. Thanks for your request! This vulnerability is in scope for the reward program. Please submit our participation form and you can start working on the development. Please keep in mind that the Tsunami Scanner Team will only be able to work at one issue at a time for each participant so please hold on the implementation work for any other requests you might have. Thanks! |
Hi @tooryx and @maoning please let me know, I want to work on this before the start of 2024 working days. |
Hi @secureness, I managed to get an ESXi running with ~tooryx |
@tooryx Thank you! It would be great if you could share a resource about running an ESXI with qemu. I'd like to look at this solution too. |
There is not really an existing resource (or I did not find it). Once I get everything working (I still have a few issues with networking), I will post a quick how-to here. |
Hi @tooryx I managed to build a nested vCenter home lab with VMware Workstation 17. |
Hi @secureness, Sorry I finalized installing VMWare ESXi on qemu and have a small guide. I will publish it at some point. I will try to import VRealize as well when I have some time so that we can proceed. ~tooryx |
I want to write a Tsunami plugin to Cover this dangerous CVE if it is possible.
Ref: https://summoning.team/blog/vmware-vrealize-network-insight-rce-cve-2023-20887/
The text was updated successfully, but these errors were encountered: