Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
kaseya unitrends backup vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2017-12477
It exists that the bpserverd proprietary protocol in Unitrends Backup (UB) prior to 10.0.0, as invoked through xinetd, has an issue in which its authentication can be bypassed. A remote attacker could use this issue to execute arbitrary commands with root privilege on the target ...
Kaseya Unitrends Backup
2 EDB exploits
8.8
CVSSv3
CVE-2017-12479
It exists that an issue in the session logic in Unitrends Backup (UB) prior to 10.0.0 allowed using the LOGDIR environment variable during a web session to elevate an existing low-privilege user to root privileges. A remote attacker with existing low-privilege credentials could t...
Kaseya Unitrends Backup
1 EDB exploit
7.8
CVSSv3
CVE-2021-43034
An issue exists in Kaseya Unitrends Backup Appliance prior to 10.5.5. A world writable file allowed local users to execute arbitrary code as the user apache, leading to privilege escalation.
Kaseya Unitrends Backup
9.8
CVSSv3
CVE-2021-43036
An issue exists in Kaseya Unitrends Backup Appliance prior to 10.5.5. The password for the PostgreSQL wguest account is weak.
Kaseya Unitrends Backup
8.8
CVSSv3
CVE-2021-43038
An issue exists in Kaseya Unitrends Backup Appliance prior to 10.5.5. The wguest account could execute commands by injecting into PostgreSQL trigger functions. This allowed privilege escalation from the wguest user to the postgres user.
Kaseya Unitrends Backup
8.8
CVSSv3
CVE-2021-43041
An issue exists in Kaseya Unitrends Backup Appliance prior to 10.5.5. A crafted HTTP request could induce a format string vulnerability in the privileged vaultServer application.
Kaseya Unitrends Backup
9.8
CVSSv3
CVE-2021-43042
An issue exists in Kaseya Unitrends Backup Appliance prior to 10.5.5. A buffer overflow existed in the vaultServer component. This was exploitable by a remote unauthenticated attacker.
Kaseya Unitrends Backup
6.5
CVSSv3
CVE-2021-43043
An issue exists in Kaseya Unitrends Backup Appliance prior to 10.5.5. The apache user could read arbitrary files such as /etc/shadow by abusing an insecure Sudo rule.
Kaseya Unitrends Backup
9.8
CVSSv3
CVE-2021-43044
An issue exists in Kaseya Unitrends Backup Appliance prior to 10.5.5. The SNMP daemon was configured with a weak default community.
Kaseya Unitrends Backup
6.5
CVSSv3
CVE-2021-43039
An issue exists in Kaseya Unitrends Backup Appliance prior to 10.5.5. The Samba file sharing service allowed anonymous read/write access.
Kaseya Unitrends Backup
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3201
CVE-2024-4779
CVE-2024-35090
CVE-2024-5084
hard-coded
CVE-2024-4985
HTML injection
CVE-2024-33655
local file inclusion
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »