Multiple Vulnerabilities in Rocket Software UniData's UniRPC server (Fixed) | Rapid7 Blog
In early 2023, Rapid7 discovered several vulnerabilities in Rocket Software UniData UniRPC. We worked with the company to fix issues and coordinate this disclosure.
In early 2023, Rapid7 discovered several vulnerabilities in Rocket Software 's UniData and UniVerse UniRPC server (and related services) running on the Linux platform. Rapid7 worked with Rocket Software to fix the issues and coordinate this disclosure. This disclosure will detail a number of different vulnerabilities, including: CVE-2023-28501: Pre-authentication heap buffer overflow in unirpcd service CVE-2023-28502: Pre-authentication stack buffer overflow in udadmin_server service CVE-2023-28503: Authentication bypass in libunidata.so's do_log_on_user() function CVE-2023-28504: Pre-authenti
saved by
related reading
- Assessing Claude Mythos Preview’s cybersecurity capabilities \ Anthropicred.anthropic.com
- GitHub - Bin4ry/UniPwn at boschko.cagithub.com
- UniBLEed: Root RCE on Any Unitree G1 Humanoid Robotboschko.ca
- All learning materials - detailed | Web Security Academyportswigger.net
- Hacker wipes Romania's entire land registry databasenews.risky.biz
- GitHub RCE Vulnerability: CVE-2026-3854 Breakdown | Wiz Blogwiz.io
- The Dirty Pipe Vulnerability — The Dirty Pipe Vulnerability documentationdirtypipe.cm4all.com
- Memory Safety Vulnerabilities | Computer Securitytextbook.cs161.org
- When MFA isn’t an option: The legacy of ROPC | Red Canaryredcanary.com
- Why We Don’t Trust the Database With Authentication – Sturdy Statisticsblog.sturdystatistics.com
- Berkeley r-commandsen.wikipedia.org
- 【資安週報】2022年7月11日到7月15日ithome.com.tw