Unitrends Backup
Vendor:
First CVE: Aug 7, 2017 · Active for 8 years
17
Total CVEs
More Total CVEs than 94% of tracked products
4.3
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
8.9
Avg CVSS
Higher Avg CVSS than 83% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Unitrends Backup over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 7, 2017
8 years ago
Most Recent CVE
Apr 15, 2022
1,565 days ago
CVE Severity & Scoring
Unitrends Backup17 CVEs
12%
35%
53%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (11.8%)
Network15 (88.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None16 (94.1%)
Unknown0 (0.0%)
Required1 (5.9%)
Privileges Required
Low6 (35.3%)
High0 (0.0%)
None11 (64.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-12478CRITICAL It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of its input parameters was not validated. A remote attacker c | Aug 7, 2017 | 9.8 | 87 | NO | YES |
CVE-2018-6328CRITICAL It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unauthenticated user to inject arbi | Mar 14, 2018 | 9.8 | 82 | NO | YES |
CVE-2017-12477CRITICAL It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xinetd, has an issue in which its authentication can be bypasse | Aug 7, 2017 | 9.8 | 78 | NO | YES |
CVE-2017-12479HIGH It was discovered that an issue in the session logic in Unitrends Backup (UB) before 10.0.0 allowed using the LOGDIR environment variable during a web session to elevate an existin | Aug 7, 2017 | 8.8 | 43 | NO | YES |
CVE-2021-43033CRITICAL An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Multiple functions in the bpserverd daemon were vulnerable to arbitrary remote code execution as root. T | Dec 6, 2021 | 9.8 | 33 | NO | NO |
CVE-2021-43035CRITICAL An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Two unauthenticated SQL injection vulnerabilities were discovered, allowing arbitrary SQL queries to be | Dec 6, 2021 | 9.8 | 32 | NO | NO |
CVE-2021-40386CRITICAL Kaseya Unitrends Client/Agent through 10.5,5 allows remote attackers to execute arbitrary code. | Apr 15, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-43044CRITICAL An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The SNMP daemon was configured with a weak default community. | Dec 6, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-43036CRITICAL An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The password for the PostgreSQL wguest account is weak. | Dec 6, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-43042CRITICAL An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A buffer overflow existed in the vaultServer component. This was exploitable by a remote unauthenticated | Dec 6, 2021 | 9.8 | 30 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (17 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
17.6% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
23.5% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (17 CVEs).
Media Mentions
Signals from CVEs in this product scope (17 CVEs).
Top CNAs Publishing CVEs For Unitrends Backup
Top CWEs
Versions
No cataloged versions.