Unitrends Backup

Vendor:

First CVE: Aug 7, 2017 · Active for 8 years

17
Total CVEs
More Total CVEs than 94% of tracked products
4.3
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
8.9
Avg CVSS
Higher Avg CVSS than 83% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Unitrends Backup over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 7, 2017
8 years ago
Most Recent CVE
Apr 15, 2022
1,565 days ago

CVE Severity & Scoring

Unitrends Backup17 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local2 (11.8%)
Network15 (88.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None16 (94.1%)
Unknown0 (0.0%)
Required1 (5.9%)
Privileges Required
Low6 (35.3%)
High0 (0.0%)
None11 (64.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of its input parameters was not validated. A remote attacker c
Aug 7, 20179.887NOYES
It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unauthenticated user to inject arbi
Mar 14, 20189.882NOYES
It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xinetd, has an issue in which its authentication can be bypasse
Aug 7, 20179.878NOYES
It was discovered that an issue in the session logic in Unitrends Backup (UB) before 10.0.0 allowed using the LOGDIR environment variable during a web session to elevate an existin
Aug 7, 20178.843NOYES
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Multiple functions in the bpserverd daemon were vulnerable to arbitrary remote code execution as root. T
Dec 6, 20219.833NONO
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Two unauthenticated SQL injection vulnerabilities were discovered, allowing arbitrary SQL queries to be
Dec 6, 20219.832NONO
Kaseya Unitrends Client/Agent through 10.5,5 allows remote attackers to execute arbitrary code.
Apr 15, 20229.831NONO
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The SNMP daemon was configured with a weak default community.
Dec 6, 20219.831NONO
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The password for the PostgreSQL wguest account is weak.
Dec 6, 20219.831NONO
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A buffer overflow existed in the vaultServer component. This was exploitable by a remote unauthenticated
Dec 6, 20219.830NONO

Exploit Exposure

Signals from CVEs in this product scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
17.6% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
23.5% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (17 CVEs).

Media Mentions

Signals from CVEs in this product scope (17 CVEs).

Top CNAs Publishing CVEs For Unitrends Backup

Top CWEs

Versions

No cataloged versions.