CVE-2023-28055
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Sep 27, 2023
Updated: Sep 29, 2023
CWE ID 285
Summary
CVE-2023-28055 is a serious vulnerability affecting Dell NetWorker Version 19.7. An unauthenticated attacker within the same network can take advantage of an improper authorization issue in the NetWorker client. By manipulating a command, they could gain complete access to the server, leading to information leaks, denial of service, and arbitrary code execution. Dell strongly advises customers to upgrade to a newer version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Dell Technologies, Inc.