CVE-2023-28055
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Dell NetWorker, Version 19.7 has an improper authorization vulnerability in the NetWorker client. An unauthenticated attacker within the same network could potentially exploit this by manipulating a command leading to gain of complete access to the server file further resulting in information leaks, denial of service, and arbitrary code execution. Dell recommends customers to upgrade at the earliest opportunity.
Dell NetWorker, versión 19.7 tiene una vulnerabilidad de autorización incorrecta en el cliente NetWorker. Un atacante no autenticado dentro de la misma red podría explotar esto manipulando un comando que conduzca a obtener acceso completo al archivo del servidor, lo que resultaría en fugas de información, denegación de servicio y ejecución de código arbitrario. Dell recomienda a los clientes actualizar lo antes posible.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2023-03-10 CVE Reserved
- 2023-09-26 CVE Published
- 2023-09-30 EPSS Updated
- 2024-09-24 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-285: Improper Authorization
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.dell.com/support/kbdoc/en-us/000218003/dsa-2023-294-security-update-for-dell-networker-nw-client-vulnerabilities | 2023-09-29 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dell Search vendor "Dell" | Networker Search vendor "Dell" for product "Networker" | >= 19.7 < 19.7.0.5 Search vendor "Dell" for product "Networker" and version " >= 19.7 < 19.7.0.5" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Networker Search vendor "Dell" for product "Networker" | >= 19.8 < 19.8.0.3 Search vendor "Dell" for product "Networker" and version " >= 19.8 < 19.8.0.3" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Networker Search vendor "Dell" for product "Networker" | >= 19.9 < 19.9.0.2 Search vendor "Dell" for product "Networker" and version " >= 19.9 < 19.9.0.2" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Networker Search vendor "Dell" for product "Networker" | 19.7.1 Search vendor "Dell" for product "Networker" and version "19.7.1" | - |
Affected
|