Lucene search

K
nvd[email protected]NVD:CVE-2023-28501
HistoryMar 29, 2023 - 8:15 p.m.

CVE-2023-28501

2023-03-2920:15:07
CWE-190
web.nvd.nist.gov
6
rocket software
unidata
universe
heap-based buffer overflow
remote code execution
unirpcd daemon

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

10

Confidence

High

EPSS

0.004

Percentile

74.0%

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based buffer overflow in the unirpcd daemon that, if successfully exploited, can lead to remote code execution as the root user.

Affected configurations

Nvd
Node
rocketsoftwareunidataRange8.2.4
OR
rocketsoftwareuniverseRange11.3.5
OR
rocketsoftwareuniverseRange12.0.012.2.1
AND
linuxlinux_kernelMatch-
VendorProductVersionCPE
rocketsoftwareunidata*cpe:2.3:a:rocketsoftware:unidata:*:*:*:*:*:*:*:*
rocketsoftwareuniverse*cpe:2.3:a:rocketsoftware:universe:*:*:*:*:*:*:*:*
linuxlinux_kernel-cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

10

Confidence

High

EPSS

0.004

Percentile

74.0%

Related for NVD:CVE-2023-28501