First published: Tue Sep 26 2023(Updated: )
Dell NetWorker, Version 19.7 has an improper authorization vulnerability in the NetWorker client. An unauthenticated attacker within the same network could potentially exploit this by manipulating a command leading to gain of complete access to the server file further resulting in information leaks, denial of service, and arbitrary code execution. Dell recommends customers to upgrade at the earliest opportunity.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC NetWorker | >=19.7<19.7.0.5 | |
Dell EMC NetWorker | >=19.8<19.8.0.3 | |
Dell EMC NetWorker | >=19.9<19.9.0.2 | |
Dell EMC NetWorker | =19.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Dell NetWorker vulnerability is CVE-2023-28055.
The severity of CVE-2023-28055 is high.
An unauthenticated attacker within the same network can exploit CVE-2023-28055 by manipulating a command to gain complete access to the server files, potentially resulting in information leaks.
Dell NetWorker Version 19.7, 19.8, and 19.9, as well as 19.7.1, are affected by CVE-2023-28055.
You can find more information about this Dell NetWorker vulnerability at the following link: [Dell Support KB Article](https://www.dell.com/support/kbdoc/en-us/000218003/dsa-2023-294-security-update-for-dell-networker-nw-client-vulnerabilities).