7.5
CVSSv2

CVE-2014-3139

Published: 02/05/2014 Updated: 05/05/2014
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

recoveryconsole/bpl/snmpd.php in Unitrends Enterprise Backup 7.3.0 allows remote malicious users to bypass authentication by setting the auth parameter to a certain string.

Vulnerable Product Search on Vulmon Subscribe to Product

unitrends enterprise backup 7.3.0

Exploits

Unitrends Enterprise Backup 730 Multiple vulnerabilities exist within this piece of software The largest one is likely the fact that the ‘auth’ string used for authorization isn’t random at all After authentication, any requests made by the browser send no cookies and only check this ‘auth’ param, which is completely insufficient Be ...