#VU72083 Improper Authentication in EMC NetWorker Server - CVE-2023-24576

 

#VU72083 Improper Authentication in EMC NetWorker Server - CVE-2023-24576

Published: February 9, 2023


Vulnerability identifier: #VU72083
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2023-24576
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
EMC NetWorker Server
Software vendor:
Dell

Description

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to an error in the authentication process in the NetWorker Client execution service (nsrexecd), when oldauth authentication method is used. A remote non-authenticated attacker can bypass authentication process and execute arbitrary code on the system.


Remediation

Install updates from vendor's website.

External links