Home/Product/kaseya unitrends backup
Product

kaseya unitrends backup

19 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2021-40386
<= 10.5.5
Kaseya Unitrends Client/Agent through 10.5,5 allows remote attackers to execute arbitrary code.
9.8CRITICAL
CVE-2021-43044
>= 10.0 and < 10.5.5
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The SNMP daemon was configured with a weak default com
9.8CRITICAL
CVE-2021-43043
>= 10.0 and < 10.5.5
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The apache user could read arbitrary files such as /et
6.5MEDIUM
CVE-2021-43042
>= 10.0 and < 10.5.5
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A buffer overflow existed in the vaultServer component
9.8CRITICAL
CVE-2021-43041
>= 10.0 and < 10.5.5
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A crafted HTTP request could induce a format string vu
8.8HIGH
CVE-2021-43040
>= 10.0 and < 10.5.5
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The privileged vaultServer could be leveraged to creat
8.8HIGH
CVE-2021-43039
>= 10.0 and < 10.5.5
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Samba file sharing service allowed anonymous read/
6.5MEDIUM
CVE-2021-43038
>= 10.0 and < 10.5.5
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The wguest account could execute commands by injecting
8.8HIGH
CVE-2021-43037
>= 10.0 and < 10.5.5
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Unitrends Windows agent was vulnerable to DLL inje
7.8HIGH
CVE-2021-43036
>= 10.0 and < 10.5.5
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The password for the PostgreSQL wguest account is weak
9.8CRITICAL
CVE-2021-43035
>= 10.0 and < 10.5.5
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Two unauthenticated SQL injection vulnerabilities were
9.8CRITICAL
CVE-2021-43034
>= 10.0 and < 10.5.5
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A world writable file allowed local users to execute a
7.8HIGH
CVE-2021-43033
>= 10.0 and < 10.5.5
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Multiple functions in the bpserverd daemon were vulner
9.8CRITICAL
CVE-2020-8427
< 10.4.1
In Unitrends Backup before 10.4.1, an HTTP request parameter was not properly sanitized, allowing for SQL injection that resulted
9.8CRITICAL
CVE-2018-6329
< 10.1.10
It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL injection,
9.8CRITICAL
CVE-2018-6328
< 10.1
It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then
9.8CRITICAL
CVE-2017-12479
<= 9.1
It was discovered that an issue in the session logic in Unitrends Backup (UB) before 10.0.0 allowed using the LOGDIR environment v
8.8HIGH
CVE-2017-12478
< 10.0
It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of its input
9.8CRITICAL
CVE-2017-12477
< 10.0
It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xinetd, has a
9.8CRITICAL
threatengine.sh