CVE-2023-28055
HIGHDell NetWorker 19.7 - Unauthenticated Improper Authorization via Command Manipulation
Title source: llmDescription
Dell NetWorker, Version 19.7 has an improper authorization vulnerability in the NetWorker client. An unauthenticated attacker within the same network could potentially exploit this by manipulating a command leading to gain of complete access to the server file further resulting in information leaks, denial of service, and arbitrary code execution. Dell recommends customers to upgrade at the earliest opportunity.
References (1)
Core 1
Core References
Patch, Vendor Advisory vendor-advisory
https://www.dell.com/support/kbdoc/en-us/000218003/dsa-2023-294-security-update-for-dell-networker-nw-client-vulnerabilities
Scores
CVSS v3
8.8
EPSS
0.0008
EPSS Percentile
22.3%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-285
Status
published
Products (2)
dell/networker
19.7.1
dell/networker
19.7 - 19.7.0.5
Published
Sep 27, 2023
Tracked Since
Feb 18, 2026