Error: QID-38020 Remote Shell Service reported on port 514 in Aria Operations for Logs
search cancel

Error: QID-38020 Remote Shell Service reported on port 514 in Aria Operations for Logs

book

Article ID: 444148

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

Vulnerability scanners such as Qualys may flag TCP port 514 as an open Remote Shell (RSH) service on VMware Aria Operations for Logs nodes. This article explains why this occurs and provides remediation steps to address the security finding.

Symptoms:

  • A security scan reports QID-38020: Remote Shell Service Open.
  • The scanner identifies an active listener on TCP port 514.
  • The security report suggests the host is vulnerable to unauthenticated remote access via RSH.

 

Environment

  • VMware Aria Operations for Logs 8.x
  • Appliance Nodes: Primary, Worker, and Integrated Load Balancer (ILB)

Cause

Vulnerability scanners misidentify TCP port 514 as "Remote Shell" because this port was historically reserved for the legacy RSH protocol. Aria Operations for Logs uses port 514 as a standard port for Syslog (TCP/UDP) ingestion. The scanner detects the Syslog service listener and incorrectly associates it with an RSH daemon based on the port number.

Resolution

The Remote Shell (RSH) daemon is not active on the appliance. This finding is a misidentification of the Syslog ingestion service.

  1. Verify Port Usage: Confirm if the environment requires log ingestion over port 514.
  2. Firewall Restriction: Use an external firewall to restrict access to TCP/UDP port 514. Ensure only authorized log-forwarding sources can connect to the appliance.
  3. Document False Positive: Provide these technical details to security auditors to whitelist the finding as a misidentified service/false positive.
  4. Upgrade: Ensure the appliance is running the latest GA release to maintain current security packages. Fixed in release 8.14 and higher. See Download Broadcom products and software for steps to download this release.

Additional Information

  • For more information on ports used by Aria Operations for Logs, see the VMware Ports and Protocols documentation.
  • To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region.