Show plain JSON{"id": "CVE-2023-28509", "cveTags": [], "metrics": {"cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 7.5, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 3.6, "exploitabilityScore": 3.9}]}, "published": "2023-03-29T21:15:08.397", "references": [{"url": "https://www.rapid7.com/blog/post/2023/03/29/multiple-vulnerabilities-in-rocket-software-unirpc-server-fixed/", "tags": ["Third Party Advisory"], "source": "cve@rapid7.com"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-327"}]}, {"type": "Secondary", "source": "cve@rapid7.com", "description": [{"lang": "en", "value": "CWE-327"}]}], "descriptions": [{"lang": "en", "value": "Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 use weak encryption for packet-level security and passwords transferred on the wire."}], "lastModified": "2023-04-06T17:23:08.237", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:rocketsoftware:unidata:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4190A053-8AEE-483F-B7EA-1A985F58D407", "versionEndIncluding": "8.2.4"}, {"criteria": "cpe:2.3:a:rocketsoftware:universe:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6E02DA68-C335-40DA-80A4-1DE974B1E0EE", "versionEndIncluding": "11.3.5"}, {"criteria": "cpe:2.3:a:rocketsoftware:universe:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4FE07875-8D74-4C39-BD7D-6044A25BC975", "versionEndIncluding": "12.2.1", "versionStartIncluding": "12.0.0"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "cve@rapid7.com"}