Dell NetWorker, Version 19.7 has an improper authorization vulnerability in the NetWorker client. An unauthenticated attacker within the same network could potentially exploit this by manipulating a command leading to gain of complete access to the server file further resulting in information leaks, denial of service, and arbitrary code execution. Dell recommends customers to upgrade at the earliest opportunity.
References
Link | Resource |
---|---|
https://www.dell.com/support/kbdoc/en-us/000218003/dsa-2023-294-security-update-for-dell-networker-nw-client-vulnerabilities | Patch Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: dell
Published: 2023-09-26T13:35:38.352Z
Updated: 2023-09-26T13:35:38.352Z
Reserved: 2023-03-10T05:01:43.872Z
Link: CVE-2023-28055
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-09-27T15:18:49.297
Modified: 2023-09-29T17:36:40.987
Link: CVE-2023-28055
JSON object: View
Redhat Information
No data.
CWE