Vulnerability scanners such as Qualys may flag TCP port 514 as an open Remote Shell (RSH) service on VMware Aria Operations for Logs nodes. This article explains why this occurs and provides remediation steps to address the security finding.
Symptoms:
Vulnerability scanners misidentify TCP port 514 as "Remote Shell" because this port was historically reserved for the legacy RSH protocol. Aria Operations for Logs uses port 514 as a standard port for Syslog (TCP/UDP) ingestion. The scanner detects the Syslog service listener and incorrectly associates it with an RSH daemon based on the port number.
The Remote Shell (RSH) daemon is not active on the appliance. This finding is a misidentification of the Syslog ingestion service.