CVE-2023-28504
NixOS vulnerability analysis and mitigation

Overview

A stack-based buffer overflow vulnerability (CVE-2023-28504) was discovered in Rocket Software's UniData and UniVerse products. The vulnerability affects UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002. This pre-authentication vulnerability exists in the libunidata.so's Ureprpcserversubmain function (NVD, Rapid7 Blog).

Technical details

The vulnerability is classified as a stack-based buffer overflow (CWE-787) that can occur in the Ureprpcserversubmain function within libunidata.so. The severity of this vulnerability is rated as CRITICAL with a CVSS v3.1 Base Score of 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating the highest level of severity (NVD).

Impact

If successfully exploited, this vulnerability can lead to remote code execution with root user privileges. The high severity score reflects the critical nature of the potential impact, allowing attackers to gain complete control over the affected system (Rapid7 Blog).

Mitigation and workarounds

Rocket Software has released patches to address this vulnerability. Users are strongly advised to upgrade to UniData version 8.2.4 build 3003, UniVerse version 11.3.5 build 1001, or UniVerse version 12.2.1 build 2002, depending on their product version (Rapid7 Blog).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-14330CRITICAL9.8
  • NixOSNixOS
  • cpe:2.3:a:mozilla:firefox_esr
NoYesDec 09, 2025
CVE-2025-14329HIGH8.8
  • NixOSNixOS
  • cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
NoYesDec 09, 2025
CVE-2025-14333HIGH8.1
  • NixOSNixOS
  • firefox
NoYesDec 09, 2025
CVE-2025-14332HIGH7.3
  • NixOSNixOS
  • firefox
NoYesDec 09, 2025
CVE-2025-14331MEDIUM6.5
  • NixOSNixOS
  • firefox
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management