Improper Authentication in EMC NetWorker Server - CVE-2023-24576

 

Improper Authentication in EMC NetWorker Server - CVE-2023-24576

Published: February 9, 2023


Vulnerability identifier: #VU72083
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-24576
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to an error in the authentication process in the NetWorker Client execution service (nsrexecd), when oldauth authentication method is used. A remote non-authenticated attacker can bypass authentication process and execute arbitrary code on the system.


Affected software

EMC NetWorker Server

How to mitigate CVE-2023-24576

Install updates from vendor's website.

EMC NetWorker Server - update to 19.7.0.3

External References

Related Security Bulletins