Rocket Software UniData < 7.3 unidata72 Remote Command Execution (credentialed check)

This script is Copyright (C) 2012-2016 Tenable Network Security, Inc.


Synopsis :

An RPC service on the remote Windows host allows commands to be run
without authentication.

Description :

The version of UniData installed on the remote Windows host is
potentially affected by a code execution vulnerability. The UniData
RPC service fails to enforce authentication on the unidata72
interface.

An unauthenticated, remote attacker can exploit this vulnerability to
execute arbitrary code on the remote host with SYSTEM level
privileges.

See also :

https://www.tenable.com/security/research/tra-2012-05
https://www.usploit.com/index.php?advisories/view/UPS-2012-0012

Solution :

Upgrade to UniData 7.3 or later.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 8.7
(CVSS2#E:ND/RL:OF/RC:ND)
Public Exploit Available : false

Family: Windows

Nessus Plugin ID: 59607 ()

Bugtraq ID: 53974

CVE ID:

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now