Kaseya

Unitrends Backup

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 4.03%
  • Veröffentlicht 06.12.2021 04:15:07
  • Zuletzt bearbeitet 21.11.2024 06:28:33

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Two unauthenticated SQL injection vulnerabilities were discovered, allowing arbitrary SQL queries to be injected and executed under the postgres superuser account. Remote cod...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 06.12.2021 04:15:07
  • Zuletzt bearbeitet 21.11.2024 06:28:33

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A world writable file allowed local users to execute arbitrary code as the user apache, leading to privilege escalation.

Exploit
  • EPSS 10.96%
  • Veröffentlicht 06.12.2021 04:15:07
  • Zuletzt bearbeitet 21.11.2024 06:28:33

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Multiple functions in the bpserverd daemon were vulnerable to arbitrary remote code execution as root. The vulnerability was caused by untrusted input (received by the server...

Exploit
  • EPSS 70.96%
  • Veröffentlicht 14.03.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 04:10:29

It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unauthenticated user to inject arbitrary commands into its /api/hosts parameters using backquotes.

Exploit
  • EPSS 76.01%
  • Veröffentlicht 07.08.2017 15:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xinetd, has an issue in which its authentication can be bypassed. A remote attacker could use this issue to execute arbitrary command...

  • EPSS 13.45%
  • Veröffentlicht 07.08.2017 15:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

It was discovered that an issue in the session logic in Unitrends Backup (UB) before 10.0.0 allowed using the LOGDIR environment variable during a web session to elevate an existing low-privilege user to root privileges. A remote attacker with existi...

Exploit
  • EPSS 81.58%
  • Veröffentlicht 07.08.2017 15:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of its input parameters was not validated. A remote attacker could use this flaw to bypass authentication and execute arbitrary comm...