HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2023-28055

CVSS 8.8v3.1pub. 2023-09-27upd. 2024-11-21

Dell NetWorker, Version 19.7 has an improper authorization vulnerability in the NetWorker client. An unauthenticated attacker within the same network could potentially exploit this by manipulating a command leading to gain of complete access to the server file further resulting in information leaks, denial of service, and arbitrary code execution. Dell recommends customers to upgrade at the earliest opportunity.

CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Dell Networker

    APP
    Dell
    19.7.119.7 – 19.7.0.5 (excl.)19.8 – 19.8.0.3 (excl.)19.9 – 19.9.0.2 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCEAuth BypassDoS
CWE
References

Related vulnerabilities

CVE-2025-21103HIGH7.8same product

Dell NetWorker Management Console, version(s) 19.11 through 19.11.0.3 & Versions prior to 19.10.0.7 contain(s)...

CVE-2025-21107HIGH7.8same product

Dell NetWorker, version(s) prior to 19.11.0.3, all versions of 19.10 & prior versions contain(s) an Unquoted S...

CVE-2024-42422HIGH8.3same product

Dell NetWorker, version(s) 19.10, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability...

CVE-2024-22432HIGH7.8same product

Networker 19.9 and all prior versions contains a Plain-text Password stored in temporary config file during b...

CVE-2023-25539HIGH8.4same product

Dell NetWorker 19.6.1.2, contains an OS command injection Vulnerability in the NetWorker client. A remote una...