← All CVEs

CVE-2023-28503

critical · 9.8

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged to bypass authentication checks and execute OS commands as the root user.

9.8
CVSS
62.1%
EPSS (exploit prob.)
99th
EPSS percentile
2023-03-29
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-798CWE-287

Affected products

VendorProductAffected versions
rocketsoftwareunidata<= 8.2.4
rocketsoftwareuniverse<= 11.3.5
rocketsoftwareuniverse>= 12.0.0, <= 12.2.1
linuxlinux_kernelall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-28503