← Vulnerability feed

Vulnerability record · CVE-2023-28506 · published 29 March 2023

CVE-2023-28506: Rocketsoftware unidata classic buffer overflow vulnerability

Rocketsoftware · Unidata

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow, where a string is copied into a buffer using a memcpy-like function and a user-provided length. This requires a valid login to exploit.

8.8 CVSS 3.1 High EPSS 0.91% · top 41.6% CWE-120 · Classic buffer overflowCWE-787 · Out-of-bounds write
8.8CVSS 3.1 base score
0.91%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow, where a string is copied into a buffer using a memcpy-like function and a user-provided length. This requires a valid login to exploit.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-28506 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-28502Rocket Software UniData/UniVerse udadmin stack buffer overflow RCERocket Software UniData and UniVerse contain a stack-based buffer overflow in the udadmin service. A remote, unauthenticated attacker can trigger the…EPSS 61%analysed9.8CVE-2023-28503Rocket Software UniData/UniVerse authentication bypass with hard-coded credentialsRocket Software UniData and UniVerse contain an authentication bypass where a special username paired with a deterministic password defeats authentic…EPSS 62%analysed9.8CVE-2023-28504Rocketsoftware unidata classic buffer overflow vulnerabilityRocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-…EPSS 1.4%9.8CVE-2023-28507Rocketsoftware unidata uncontrolled resource consumption vulnerabilityRocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a memory…EPSS 0.92%9.8CVE-2023-28501Rocketsoftware unidata integer overflow vulnerabilityRocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-b…EPSS 1.4%8.8CVE-2023-28505Rocketsoftware unidata classic buffer overflow vulnerabilityRocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a buffer…EPSS 0.84%8.8CVE-2023-28508Rocketsoftware unidata classic buffer overflow vulnerabilityRocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-b…EPSS 0.90%7.5CVE-2023-28509Rocketsoftware unidata broken cryptographic algorithm vulnerabilityRocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 use weak encryption …EPSS 0.28%

Source: NIST National Vulnerability Database (record CVE-2023-28506), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.