← Back to browse · API

CVE-2023-28502

Severity
CRITICAL
CVSS
9.8
EPSS
0.61102
Risk score
60.59
CISA KEV
No
PoC
No
Published
2023-03-29
Modified
2025-02-18
First seen
2026-08-07
Aliases
EUVD-2023-32172, GHSA-J6JR-7HQV-4MP7
Products
Rocket Software:UniData 0 <8.2.43.3003, Rocket Software:UniVerse 0 <11.3.5.1001, Rocket Software:UniVerse 0 <12.2.1.2002
Sources
euvd EUVD-2023-32172

Description

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow in the "udadmin" service that can lead to remote code execution as the root user.

References