flâneur — a map of the web's best reading

Multiple Vulnerabilities in Rocket Software UniData's UniRPC server (Fixed) | Rapid7 Blog

rapid7.com · 7,540 words · saved by 1 readers

In early 2023, Rapid7 discovered several vulnerabilities in Rocket Software UniData UniRPC. We worked with the company to fix issues and coordinate this disclosure.

In early 2023, Rapid7 discovered several vulnerabilities in Rocket Software 's UniData and UniVerse UniRPC server (and related services) running on the Linux platform. Rapid7 worked with Rocket Software to fix the issues and coordinate this disclosure. This disclosure will detail a number of different vulnerabilities, including: CVE-2023-28501: Pre-authentication heap buffer overflow in unirpcd service CVE-2023-28502: Pre-authentication stack buffer overflow in udadmin_server service CVE-2023-28503: Authentication bypass in libunidata.so's do_log_on_user() function CVE-2023-28504: Pre-authenti

Explore this link on the map →

saved by

related reading