CVE-2023-28509: Weak encryption in UniRPC protocol
Published Mar 29, 2023
·Updated
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 use weak encryption for packet-level security and passwords transferred on the wire.
Affected Software
8 affected components
All of the following
Any of the following
Rocketsoftware Unidata<=8.2.4
Rocketsoftware Universe<=11.3.5
Rocketsoftware Universe>=12.0.0<=12.2.1
Linux Linux kernel
Rocketsoftware Unidata<=8.2.4
Rocketsoftware Universe<=11.3.5
Rocketsoftware Universe>=12.0.0<=12.2.1
Linux Linux kernel
Event History
Mar 29, 2023
CVE Published
via MITRE·08:18 PM
Data Sourced
via MITRE·08:18 PM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-28509.
2
Which software versions are affected by this vulnerability?
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 are affected.
3
What is the severity of vulnerability CVE-2023-28509?
The severity of vulnerability CVE-2023-28509 is high with a severity value of 7.5.
4
What is the CWE (Common Weakness Enumeration) for this vulnerability?
The CWE for this vulnerability is CWE-326 and CWE-327.
5
How can I fix the vulnerability CVE-2023-28509?
To fix the vulnerability CVE-2023-28509, update Rocket Software UniData to version 8.2.4 build 3003 or later, and update UniVerse to version 11.3.5 build 1001 or 12.2.1 build 2002 or later.