CRITICAL

CVE-2023-28503

CVSS v3

9.8

CRITICAL

EPSS Score

63.2%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged to bypass authentication checks and execute OS commands as the root user.

Technical details

Published
3/29/2023

Frequently asked questions

What is CVE-2023-28503?

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged to bypass authentication checks and execute OS commands as the root user.

Is CVE-2023-28503 actively exploited?

Active exploitation of CVE-2023-28503 has not been confirmed. The EPSS score is 63.2%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2023-28503?

CVE-2023-28503 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2023-28503 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.