Cloud Backup Suite
Vendor:
First CVE: Jul 26, 2019 · Active for 7 years
7
Total CVEs
More Total CVEs than 85% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 63% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Cloud Backup Suite over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 26, 2019
7 years ago
Most Recent CVE
Sep 21, 2022
1,406 days ago
CVE Severity & Scoring
Cloud Backup Suite7 CVEs
14%
86%
All CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (85.7%)
Unknown0 (0.0%)
Required1 (14.3%)
Privileges Required
Low2 (28.6%)
High2 (28.6%)
None3 (42.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10267HIGH An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to upload a file into any directory of the server. One can inse | Jul 26, 2019 | 8.8 | 83 | NO | YES |
CVE-2019-10266HIGH An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When sending an out-of-bounds XML document to a URL, it is possible to read the file structure and even the con | Jul 26, 2019 | 7.5 | 40 | NO | YES |
CVE-2022-37027HIGH Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options. Administrators that can modify the Runtime Options in the web interface can inject | Sep 21, 2022 | 7.2 | 35 | NO | NO |
CVE-2019-10265HIGH An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. On the /cbs/system/ShowAdvanced.do "File Explorer" screen, it is possible to change the directory in the JavaSc | Jul 26, 2019 | 7.5 | 25 | NO | NO |
CVE-2019-10264HIGH An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. With a valid administrator account, the "Move / Import / Export Users" screen has an Import Users option. This | Jul 26, 2019 | 7.2 | 23 | NO | NO |
CVE-2020-5846HIGH An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.3.0.30 via a "PUT /obs/obm7/file/upload" request with the base64-encoded pathname in t | Jan 6, 2020 | 8.8 | 22 | NO | NO |
CVE-2019-10263MEDIUM An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When creating a trial account, it is possible to inject XSS in the Alias field, allowing the attacker to retrie | Jul 26, 2019 | 6.1 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
14.3% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
28.6% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Cloud Backup Suite
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.1.4.0 | 1 | 7.2 | 21.7% | 0 | 0 |
| 8.3.0.30 | 1 | 8.8 | 1.4% | 0 | 0 |