unitrends records
10 published records for vendor unitrends.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 10%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-287 Improper Authentication2
- CWE-20 Improper Input Validation2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
57Plan | CVE-2018-6329Weaponized | It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL injection, allowing aunitrends · backup · CWE-89 | Critical9.8 | — | 61.2% | Mar 14, 2018 |
42Plan | CVE-2014-3008Proof of concept | Unitrends Enterprise Backup 7.3.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the comm paramunitrends · enterprise backup · CWE-78 | Critical10.0 | — | 7.0% | Apr 28, 2014 |
41Plan | CVE-2017-7280No exploit | An issue was discovered in api/includes/systems.php in Unitrends Enterprise Backup before 9.0.0.unitrends · enterprise backup · CWE-20 | Critical9.8 | — | 6.2% | Apr 12, 2017 |
40Plan | CVE-2017-7279No exploit | An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" coounitrends · enterprise backup · CWE-565 | Critical9.8 | — | 4.4% | Apr 12, 2017 |
39Monitor | CVE-2020-8427No exploit | In Unitrends Backup before 10.4.1, an HTTP request parameter was not properly sanitized, allowing for SQL injection that resulted in an authunitrends · backup · CWE-89 | Critical9.8 | — | 1.5% | Feb 17, 2020 |
36Monitor | CVE-2017-7281No exploit | An issue was discovered in Unitrends Enterprise Backup before 9.1.2.unitrends · enterprise backup · CWE-434 | High8.8 | — | 4.3% | Apr 12, 2017 |
36Monitor | CVE-2017-7283No exploit | An authenticated user of Unitrends Enterprise Backup before 9.1.2 can execute arbitrary OS commands by sending a specially crafted filename unitrends · enterprise backup · CWE-20 | High8.8 | — | 4.3% | Apr 19, 2017 |
36Monitor | CVE-2017-7284No exploit | An attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api/includes/users.php to change unitrends · enterprise backup · CWE-287 | High8.8 | — | 2.7% | Apr 12, 2017 |
31Monitor | CVE-2014-3139Proof of concept | recoveryconsole/bpl/snmpd.php in Unitrends Enterprise Backup 7.3.0 allows remote attackers to bypass authentication by setting the auth paraunitrends · enterprise backup · CWE-287 | High7.5 | — | 3.3% | May 2, 2014 |
23Monitor | CVE-2017-7282No exploit | An issue was discovered in Unitrends Enterprise Backup before 9.1.1.unitrends · enterprise backup · CWE-200 | Medium5.5 | — | 4.3% | Apr 19, 2017 |
- CVE-2018-632957Plan
It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL injection, allowing a
CriticalCVSS 9.8WeaponizedEPSS 61%unitrends · backupMar 14, 2018
- CVE-2014-300842Plan
Unitrends Enterprise Backup 7.3.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the comm param
CriticalCVSS 10.0Proof of conceptEPSS 7%unitrends · enterprise backupApr 28, 2014
- CVE-2017-728041Plan
An issue was discovered in api/includes/systems.php in Unitrends Enterprise Backup before 9.0.0.
CriticalCVSS 9.8No exploitEPSS 6%unitrends · enterprise backupApr 12, 2017
- CVE-2017-727940Plan
An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" coo
CriticalCVSS 9.8No exploitEPSS 4%unitrends · enterprise backupApr 12, 2017
- CVE-2020-842739Monitor
In Unitrends Backup before 10.4.1, an HTTP request parameter was not properly sanitized, allowing for SQL injection that resulted in an auth
CriticalCVSS 9.8No exploitEPSS 2%unitrends · backupFeb 17, 2020
- CVE-2017-728136Monitor
An issue was discovered in Unitrends Enterprise Backup before 9.1.2.
HighCVSS 8.8No exploitEPSS 4%unitrends · enterprise backupApr 12, 2017
- CVE-2017-728336Monitor
An authenticated user of Unitrends Enterprise Backup before 9.1.2 can execute arbitrary OS commands by sending a specially crafted filename
HighCVSS 8.8No exploitEPSS 4%unitrends · enterprise backupApr 19, 2017
- CVE-2017-728436Monitor
An attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api/includes/users.php to change
HighCVSS 8.8No exploitEPSS 3%unitrends · enterprise backupApr 12, 2017
- CVE-2014-313931Monitor
recoveryconsole/bpl/snmpd.php in Unitrends Enterprise Backup 7.3.0 allows remote attackers to bypass authentication by setting the auth para
HighCVSS 7.5Proof of conceptEPSS 3%unitrends · enterprise backupMay 2, 2014
- CVE-2017-728223Monitor
An issue was discovered in Unitrends Enterprise Backup before 9.1.1.
MediumCVSS 5.5No exploitEPSS 4%unitrends · enterprise backupApr 19, 2017