Unitrends develops enterprise backup and recovery solutions that protect critical business data and systems, products that sit at the intersection of authentication, data access, and command execution in infrastructure environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, concentrating on authentication bypass, input validation, SQL injection, and OS command injection—weakness classes that expose backup systems to both unauthorized access and lateral movement. Defenders should prioritize patches for this vendor given the sensitivity of backup infrastructure and its role in disaster recovery; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Unitrends over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-6329CRITICAL It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL injection, allowing a remote attacker to place a privilege es | Mar 14, 2018 | 9.8 | 79 | NO | YES |
CVE-2014-3008HIGH Unitrends Enterprise Backup 7.3.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the comm parameter to recoveryconsole/bpl/snmpd.php. | Apr 28, 2014 | 10.0 | 37 | NO | YES |
CVE-2017-7279CRITICAL An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" cookie issued at login. | Apr 12, 2017 | 9.8 | 31 | NO | NO |
CVE-2020-8427CRITICAL In Unitrends Backup before 10.4.1, an HTTP request parameter was not properly sanitized, allowing for SQL injection that resulted in an authentication bypass. | Feb 17, 2020 | 9.8 | 30 | NO | NO |
CVE-2017-7283HIGH An authenticated user of Unitrends Enterprise Backup before 9.1.2 can execute arbitrary OS commands by sending a specially crafted filename to the /api/restore/download-files endpo | Apr 20, 2017 | 8.8 | 30 | NO | NO |
CVE-2014-3139HIGH recoveryconsole/bpl/snmpd.php in Unitrends Enterprise Backup 7.3.0 allows remote attackers to bypass authentication by setting the auth parameter to a certain string. | May 2, 2014 | 7.5 | 29 | NO | YES |
CVE-2017-7281HIGH An issue was discovered in Unitrends Enterprise Backup before 9.1.2. A lack of sanitization of user input in the createReportName and saveReport functions in recoveryconsole/bpl/re | Apr 12, 2017 | 8.8 | 28 | NO | NO |
CVE-2017-7280CRITICAL An issue was discovered in api/includes/systems.php in Unitrends Enterprise Backup before 9.0.0. User input is not properly filtered before being sent to a popen function. This all | Apr 12, 2017 | 9.8 | 28 | NO | NO |
CVE-2017-7284HIGH An attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api/includes/users.php to change the password of the logged in account wi | Apr 12, 2017 | 8.8 | 27 | NO | NO |
CVE-2017-7282MEDIUM An issue was discovered in Unitrends Enterprise Backup before 9.1.1. The function downloadFile in api/includes/restore.php blindly accepts any filename passed to /api/restore/downl | Apr 20, 2017 | 5.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Unitrends.
Media articles that mention a CVE ID that affects a product developed by Unitrends — matched by CVE ID, not by vendor name.