peter bassill · operator
$ cve CVE-2023-28503 JSON

CVE-2023-28503

9.8
CRITICAL · CVSS 3.1 · EPSS 62.1% (pctl 99)

Patch early

EPSS 62.1% — above the 10% action threshold.

Description

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged to bypass authentication checks and execute OS commands as the root user.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS62.14% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-798
On CISA KEVno
Public exploitnone known
Published2023-03-29
Last modified2026-06-17

Affected (3)

VendorProduct
linuxlinux kernel
rocketsoftwareunidata
rocketsoftwareuniverse

References

→ the Explorer  ·  watch your stack  ·  NVD