Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
unitrends backup vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2017-12479
It exists that an issue in the session logic in Unitrends Backup (UB) prior to 10.0.0 allowed using the LOGDIR environment variable during a web session to elevate an existing low-privilege user to root privileges. A remote attacker with existing low-privilege credentials could t...
Kaseya Unitrends Backup
1 EDB exploit
7.8
CVSSv3
CVE-2021-43037
An issue exists in Kaseya Unitrends Backup Appliance prior to 10.5.5. The Unitrends Windows agent was vulnerable to DLL injection and binary planting due to insecure default permissions. This allowed privilege escalation from an unprivileged user to SYSTEM.
Kaseya Unitrends Backup
6.5
CVSSv3
CVE-2021-43039
An issue exists in Kaseya Unitrends Backup Appliance prior to 10.5.5. The Samba file sharing service allowed anonymous read/write access.
Kaseya Unitrends Backup
9.8
CVSSv3
CVE-2021-43044
An issue exists in Kaseya Unitrends Backup Appliance prior to 10.5.5. The SNMP daemon was configured with a weak default community.
Kaseya Unitrends Backup
9.8
CVSSv3
CVE-2021-43036
An issue exists in Kaseya Unitrends Backup Appliance prior to 10.5.5. The password for the PostgreSQL wguest account is weak.
Kaseya Unitrends Backup
9.8
CVSSv3
CVE-2018-6328
It exists that the Unitrends Backup (UB) prior to 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unauthenticated user to inject arbitrary commands into its /api/hosts parameters using backquotes.
Kaseya Unitrends Backup
1 EDB exploit
9.8
CVSSv3
CVE-2017-7280
An issue exists in api/includes/systems.php in Unitrends Enterprise Backup prior to 9.0.0. User input is not properly filtered before being sent to a popen function. This allows for remote code execution by sending a specially crafted user variable.
Unitrends Enterprise Backup
8.8
CVSSv3
CVE-2017-7281
An issue exists in Unitrends Enterprise Backup prior to 9.1.2. A lack of sanitization of user input in the createReportName and saveReport functions in recoveryconsole/bpl/reports.php allows for an authenticated user to create a randomly named file on disk with a user-controlled ...
Unitrends Enterprise Backup
5.5
CVSSv3
CVE-2017-7282
An issue exists in Unitrends Enterprise Backup prior to 9.1.1. The function downloadFile in api/includes/restore.php blindly accepts any filename passed to /api/restore/download as valid. This allows an authenticated malicious user to read any file in the filesystem that the web ...
Unitrends Enterprise Backup
8.8
CVSSv3
CVE-2017-7284
An attacker that has hijacked a Unitrends Enterprise Backup (prior to 9.1.2) web server session can leverage api/includes/users.php to change the password of the logged in account without knowing the current password. This allows for an account takeover.
Unitrends Enterprise Backup
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »