Multiple Vulnerabilities in Rocket Software UniData's UniRPC server (Fixed) | Rapid7 Blog
In early 2023, Rapid7 discovered several vulnerabilities in Rocket Software UniData UniRPC. We worked with the company to fix issues and coordinate this disclosure.
In early 2023, Rapid7 discovered several vulnerabilities in Rocket Software 's UniData and UniVerse UniRPC server (and related services) running on the Linux platform. Rapid7 worked with Rocket Software to fix the issues and coordinate this disclosure. This disclosure will detail a number of different vulnerabilities, including: CVE-2023-28501: Pre-authentication heap buffer overflow in unirpcd service CVE-2023-28502: Pre-authentication stack buffer overflow in udadmin_server service CVE-2023-28503: Authentication bypass in libunidata.so's do_log_on_user() function CVE-2023-28504: Pre-authenti
Explore this link on the map →saved by
related reading
- Assessing Claude Mythos Preview’s cybersecurity capabilities \ Anthropicred.anthropic.com
- All learning materials - detailed | Web Security Academyportswigger.net
- GitHub RCE Vulnerability: CVE-2026-3854 Breakdown | Wiz Blogwiz.io
- The Dirty Pipe Vulnerability — The Dirty Pipe Vulnerability documentationdirtypipe.cm4all.com
- Memory Safety Vulnerabilities | Computer Securitytextbook.cs161.org
- When MFA isn’t an option: The legacy of ROPC | Red Canaryredcanary.com
- Metasploitable Project: Lesson 7: Exploiting UnrealIRCD 3.2.8.1computersecuritystudent.com
- From Naptime to Big Sleep: Using Large Language Models To Catch Vulnerabilities In Real-World Code - Project Zerogoogleprojectzero.blogspot.com
- Hacker wipes Romania's entire land registry databasenews.risky.biz
- Legacy authentication: The curious case of BAV2ROPCredcanary.com
- Zenbleedlock.cmpxchg8b.com
- Security incident disclosure — July 2026huggingface.co