Dell NetWorker, Version 19.7 has an improper authorization vulnerability in the NetWorker client. An unauthenticated attacker within the same network could potentially exploit this by manipulating a command leading to gain of complete access to the server file further resulting in information leaks, denial of service, and arbitrary code execution. Dell recommends customers to upgrade at the earliest opportunity.
History

Tue, 24 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published: 2023-09-26T13:35:38.352Z

Updated: 2024-09-24T13:20:14.242Z

Reserved: 2023-03-10T05:01:43.872Z

Link: CVE-2023-28055

cve-icon Vulnrichment

Updated: 2024-08-02T12:30:22.791Z

cve-icon NVD

Status : Modified

Published: 2023-09-27T15:18:49.297

Modified: 2024-11-21T07:54:14.803

Link: CVE-2023-28055

cve-icon Redhat

No data.