Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
kaseya unitrends backup vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2021-43036
An issue exists in Kaseya Unitrends Backup Appliance prior to 10.5.5. The password for the PostgreSQL wguest account is weak.
Kaseya Unitrends Backup
8.8
CVSSv3
CVE-2021-43038
An issue exists in Kaseya Unitrends Backup Appliance prior to 10.5.5. The wguest account could execute commands by injecting into PostgreSQL trigger functions. This allowed privilege escalation from the wguest user to the postgres user.
Kaseya Unitrends Backup
8.8
CVSSv3
CVE-2021-43040
An issue exists in Kaseya Unitrends Backup Appliance prior to 10.5.5. The privileged vaultServer could be leveraged to create arbitrary writable files, leading to privilege escalation.
Kaseya Unitrends Backup
8.8
CVSSv3
CVE-2021-43041
An issue exists in Kaseya Unitrends Backup Appliance prior to 10.5.5. A crafted HTTP request could induce a format string vulnerability in the privileged vaultServer application.
Kaseya Unitrends Backup
6.5
CVSSv3
CVE-2021-43043
An issue exists in Kaseya Unitrends Backup Appliance prior to 10.5.5. The apache user could read arbitrary files such as /etc/shadow by abusing an insecure Sudo rule.
Kaseya Unitrends Backup
9.8
CVSSv3
CVE-2017-12478
It exists that the api/storage web interface in Unitrends Backup (UB) prior to 10.0.0 has an issue in which one of its input parameters was not validated. A remote attacker could use this flaw to bypass authentication and execute arbitrary commands with root privilege on the targ...
Kaseya Unitrends Backup
3 EDB exploits
8.8
CVSSv3
CVE-2017-12479
It exists that an issue in the session logic in Unitrends Backup (UB) prior to 10.0.0 allowed using the LOGDIR environment variable during a web session to elevate an existing low-privilege user to root privileges. A remote attacker with existing low-privilege credentials could t...
Kaseya Unitrends Backup
1 EDB exploit
8.8
CVSSv3
CVE-2021-40385
An issue exists in the server software in Kaseya Unitrends Backup Software prior to 10.5.5-2. There is a privilege escalation from read-only user to admin.
Kaseya Unitrends Backup Software
8.8
CVSSv3
CVE-2021-40387
An issue exists in the server software in Kaseya Unitrends Backup Software prior to 10.5.5-2. There is authenticated remote code execution.
Kaseya Unitrends Backup Software
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
TCP
CVE-2024-4577
CVE-2024-2695
CVE-2024-31870
injection
CVE-2024-3813
arbitrary code
CVE-2024-27801
CVE-2024-30120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2