CVE-2021-40386
- EPSS 2.51%
- Veröffentlicht 15.04.2022 05:15:06
- Zuletzt bearbeitet 21.11.2024 06:24:00
Kaseya Unitrends Client/Agent through 10.5,5 allows remote attackers to execute arbitrary code.
CVE-2021-43037
- EPSS 0.05%
- Veröffentlicht 06.12.2021 04:15:07
- Zuletzt bearbeitet 21.11.2024 06:28:34
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Unitrends Windows agent was vulnerable to DLL injection and binary planting due to insecure default permissions. This allowed privilege escalation from an unprivileged us...
CVE-2021-43044
- EPSS 0.61%
- Veröffentlicht 06.12.2021 04:15:07
- Zuletzt bearbeitet 21.11.2024 06:28:35
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The SNMP daemon was configured with a weak default community.
CVE-2021-43043
- EPSS 0.39%
- Veröffentlicht 06.12.2021 04:15:07
- Zuletzt bearbeitet 21.11.2024 06:28:34
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The apache user could read arbitrary files such as /etc/shadow by abusing an insecure Sudo rule.
CVE-2021-43042
- EPSS 3.28%
- Veröffentlicht 06.12.2021 04:15:07
- Zuletzt bearbeitet 21.11.2024 06:28:34
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A buffer overflow existed in the vaultServer component. This was exploitable by a remote unauthenticated attacker.
CVE-2021-43041
- EPSS 1.42%
- Veröffentlicht 06.12.2021 04:15:07
- Zuletzt bearbeitet 21.11.2024 06:28:34
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A crafted HTTP request could induce a format string vulnerability in the privileged vaultServer application.
CVE-2021-43040
- EPSS 0.74%
- Veröffentlicht 06.12.2021 04:15:07
- Zuletzt bearbeitet 21.11.2024 06:28:34
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The privileged vaultServer could be leveraged to create arbitrary writable files, leading to privilege escalation.
CVE-2021-43039
- EPSS 0.29%
- Veröffentlicht 06.12.2021 04:15:07
- Zuletzt bearbeitet 21.11.2024 06:28:34
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Samba file sharing service allowed anonymous read/write access.
CVE-2021-43038
- EPSS 2.26%
- Veröffentlicht 06.12.2021 04:15:07
- Zuletzt bearbeitet 21.11.2024 06:28:34
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The wguest account could execute commands by injecting into PostgreSQL trigger functions. This allowed privilege escalation from the wguest user to the postgres user.
CVE-2021-43036
- EPSS 0.61%
- Veröffentlicht 06.12.2021 04:15:07
- Zuletzt bearbeitet 21.11.2024 06:28:33
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The password for the PostgreSQL wguest account is weak.