CVE-2026-5057 Details
Description
ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of ATEN Unizon. Authentication is not required to exploit this vulnerability. The specific flaw exists within the RpcProvider class. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-29041.
A denial-of-service vulnerability has been identified in ATEN Unizon versions prior to V2.7.262. The issue arises in the RpcProvider class, where the lack of authentication allows remote attackers to access functionality and create a denial-of-service condition by sending specially crafted requests. The affected service uses Java ObjectInputStream for object deserialization without proper authentication controls, leading to repeated service restarts and disruption.
Users are advised to upgrade to ATEN Unizon version V2.7.263.001, which addresses the vulnerability and eliminates the denial-of-service risk. If the upgrade cannot be performed immediately, users can restrict network access to the affected RPC service, limiting exposure of TCP port 1829 to trusted hosts only, or disable the service if it is not required until the upgrade can be completed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.aten.com/global/en/supportcenter/info/security-advisory/26/ | [email protected] | |
| https://www.zerodayinitiative.com/advisories/ZDI-26-272/ | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 29, 2026 | New CVE Received | [email protected] |
| Jul 29, 2026 | CVE Modified | CISA-ADP |