Vulnerability Description
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based buffer overflow in the unirpcd daemon that, if successfully exploited, can lead to remote code execution as the root user.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rocketsoftware | Unidata | <= 8.2.4 |
| Rocketsoftware | Universe | <= 11.3.5 |
| Linux | Linux Kernel | - |
Related Weaknesses (CWE)
References
- https://www.rapid7.com/blog/post/2023/03/29/multiple-vulnerabilities-in-rocket-sThird Party Advisory
- https://www.rapid7.com/blog/post/2023/03/29/multiple-vulnerabilities-in-rocket-sThird Party Advisory
FAQ
What is CVE-2023-28501?
CVE-2023-28501 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based buffer overflow in the unirpcd daemon that, if...
How severe is CVE-2023-28501?
CVE-2023-28501 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-28501?
Check the references section above for vendor advisories and patch information. Affected products include: Rocketsoftware Unidata, Rocketsoftware Universe, Linux Linux Kernel.