Kaseya
Kaseya Unitrends Backup: vulnerabilidades y CVE
Kaseya Unitrends Backup tiene 17 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses0
Críticas9
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-40386 | Crítica (9.8) | 1.9% | — | 15 abr 2022 | Kaseya Unitrends Client/Agent through 10.5,5 allows remote attackers to execute arbitrary code. |
| CVE-2021-43044 | Crítica (9.8) | 1.9% | — | 6 dic 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The SNMP daemon was configured with a weak default community. |
| CVE-2021-43043 | Media (6.5) | 1.5% | — | 6 dic 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The apache user could read arbitrary files such as /etc/shadow by abusing an insecure Sudo rule. |
| CVE-2021-43042 | Crítica (9.8) | 3.0% | — | 6 dic 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A buffer overflow existed in the vaultServer component. This was exploitable by a remote unauthenticated attacker. |
| CVE-2021-43041 | Alta (8.8) | 2.4% | — | 6 dic 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A crafted HTTP request could induce a format string vulnerability in the privileged vaultServer application. |
| CVE-2021-43040 | Alta (8.8) | 1.8% | — | 6 dic 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The privileged vaultServer could be leveraged to create arbitrary writable files, leading to privilege escalation. |
| CVE-2021-43039 | Media (6.5) | 1.3% | — | 6 dic 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Samba file sharing service allowed anonymous read/write access. |
| CVE-2021-43038 | Alta (8.8) | 2.3% | — | 6 dic 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The wguest account could execute commands by injecting into PostgreSQL trigger functions. This allowed privilege escalation from the wguest… |
| CVE-2021-43037 | Alta (7.8) | 0.52% | — | 6 dic 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Unitrends Windows agent was vulnerable to DLL injection and binary planting due to insecure default permissions. This allowed privilege… |
| CVE-2021-43036 | Crítica (9.8) | 1.9% | — | 6 dic 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The password for the PostgreSQL wguest account is weak. |
| CVE-2021-43035 | Crítica (9.8) | 3.4% | — | 6 dic 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Two unauthenticated SQL injection vulnerabilities were discovered, allowing arbitrary SQL queries to be injected and executed under the… |
| CVE-2021-43034 | Alta (7.8) | 0.45% | — | 6 dic 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A world writable file allowed local users to execute arbitrary code as the user apache, leading to privilege escalation. |
| CVE-2021-43033 | Crítica (9.8) | 6.2% | — | 6 dic 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Multiple functions in the bpserverd daemon were vulnerable to arbitrary remote code execution as root. The vulnerability was caused by… |
| CVE-2018-6328 | Crítica (9.8) | 64% | — | 14 mar 2018 | It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unauthenticated user to inject arbitrary commands into its /api/hosts… |
| CVE-2017-12479 | Alta (8.8) | 12% | — | 7 ago 2017 | It was discovered that an issue in the session logic in Unitrends Backup (UB) before 10.0.0 allowed using the LOGDIR environment variable during a web session to elevate an existing low-privilege user to root… |
| CVE-2017-12478 | Crítica (9.8) | 78% | — | 7 ago 2017 | It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of its input parameters was not validated. A remote attacker could use this flaw to bypass… |
| CVE-2017-12477 | Crítica (9.8) | 68% | — | 7 ago 2017 | It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xinetd, has an issue in which its authentication can be bypassed. A remote attacker could use this… |