Lucene search

K
cveRapid7CVE-2023-28503
HistoryMar 29, 2023 - 9:15 p.m.

CVE-2023-28503

2023-03-2921:15:08
CWE-798
CWE-287
rapid7
web.nvd.nist.gov
32
cve-2023-28503
rocket software
unidata
universe
authentication bypass
vulnerability
os commands
nvd

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.035

Percentile

91.8%

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged to bypass authentication checks and execute OS commands as the root user.

Affected configurations

Nvd
Node
rocketsoftwareunidataRange8.2.4
OR
rocketsoftwareuniverseRange11.3.5
OR
rocketsoftwareuniverseRange12.0.012.2.1
AND
linuxlinux_kernelMatch-
VendorProductVersionCPE
rocketsoftwareunidata*cpe:2.3:a:rocketsoftware:unidata:*:*:*:*:*:*:*:*
rocketsoftwareuniverse*cpe:2.3:a:rocketsoftware:universe:*:*:*:*:*:*:*:*
linuxlinux_kernel-cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Linux"
    ],
    "product": "UniData",
    "vendor": "Rocket Software",
    "versions": [
      {
        "lessThan": "8.2.43.3003",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Linux"
    ],
    "product": "UniVerse",
    "vendor": "Rocket Software",
    "versions": [
      {
        "lessThan": "11.3.5.1001",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      },
      {
        "lessThan": "12.2.1.2002",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  }
]

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.035

Percentile

91.8%