Записи unitrends
10 опубликованных записей вендора unitrends.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 10 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-287 Improper Authentication2
- CWE-20 Improper Input Validation2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
10 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
57В плане | CVE-2018-6329Готовый эксплойт | It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL injection, allowing aunitrends · backup · CWE-89 | Критическая9,8 | — | 61,2 % | 14 мар. 2018 г. |
42В плане | CVE-2014-3008Proof of concept | Unitrends Enterprise Backup 7.3.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the comm paramunitrends · enterprise backup · CWE-78 | Критическая10,0 | — | 7,0 % | 28 апр. 2014 г. |
41В плане | CVE-2017-7280Эксплойта нет | An issue was discovered in api/includes/systems.php in Unitrends Enterprise Backup before 9.0.0.unitrends · enterprise backup · CWE-20 | Критическая9,8 | — | 6,2 % | 12 апр. 2017 г. |
40В плане | CVE-2017-7279Эксплойта нет | An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" coounitrends · enterprise backup · CWE-565 | Критическая9,8 | — | 4,4 % | 12 апр. 2017 г. |
39Наблюдать | CVE-2020-8427Эксплойта нет | In Unitrends Backup before 10.4.1, an HTTP request parameter was not properly sanitized, allowing for SQL injection that resulted in an authunitrends · backup · CWE-89 | Критическая9,8 | — | 1,5 % | 17 февр. 2020 г. |
36Наблюдать | CVE-2017-7281Эксплойта нет | An issue was discovered in Unitrends Enterprise Backup before 9.1.2.unitrends · enterprise backup · CWE-434 | Высокая8,8 | — | 4,3 % | 12 апр. 2017 г. |
36Наблюдать | CVE-2017-7283Эксплойта нет | An authenticated user of Unitrends Enterprise Backup before 9.1.2 can execute arbitrary OS commands by sending a specially crafted filename unitrends · enterprise backup · CWE-20 | Высокая8,8 | — | 4,3 % | 19 апр. 2017 г. |
36Наблюдать | CVE-2017-7284Эксплойта нет | An attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api/includes/users.php to change unitrends · enterprise backup · CWE-287 | Высокая8,8 | — | 2,7 % | 12 апр. 2017 г. |
31Наблюдать | CVE-2014-3139Proof of concept | recoveryconsole/bpl/snmpd.php in Unitrends Enterprise Backup 7.3.0 allows remote attackers to bypass authentication by setting the auth paraunitrends · enterprise backup · CWE-287 | Высокая7,5 | — | 3,3 % | 2 мая 2014 г. |
23Наблюдать | CVE-2017-7282Эксплойта нет | An issue was discovered in Unitrends Enterprise Backup before 9.1.1.unitrends · enterprise backup · CWE-200 | Средняя5,5 | — | 4,3 % | 19 апр. 2017 г. |
- CVE-2018-632957В плане
It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL injection, allowing a
КритическаяCVSS 9,8Готовый эксплойтEPSS 61 %unitrends · backup14 мар. 2018 г.
- CVE-2014-300842В плане
Unitrends Enterprise Backup 7.3.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the comm param
КритическаяCVSS 10,0Proof of conceptEPSS 7 %unitrends · enterprise backup28 апр. 2014 г.
- CVE-2017-728041В плане
An issue was discovered in api/includes/systems.php in Unitrends Enterprise Backup before 9.0.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %unitrends · enterprise backup12 апр. 2017 г.
- CVE-2017-727940В плане
An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" coo
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %unitrends · enterprise backup12 апр. 2017 г.
- CVE-2020-842739Наблюдать
In Unitrends Backup before 10.4.1, an HTTP request parameter was not properly sanitized, allowing for SQL injection that resulted in an auth
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %unitrends · backup17 февр. 2020 г.
- CVE-2017-728136Наблюдать
An issue was discovered in Unitrends Enterprise Backup before 9.1.2.
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %unitrends · enterprise backup12 апр. 2017 г.
- CVE-2017-728336Наблюдать
An authenticated user of Unitrends Enterprise Backup before 9.1.2 can execute arbitrary OS commands by sending a specially crafted filename
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %unitrends · enterprise backup19 апр. 2017 г.
- CVE-2017-728436Наблюдать
An attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api/includes/users.php to change
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %unitrends · enterprise backup12 апр. 2017 г.
- CVE-2014-313931Наблюдать
recoveryconsole/bpl/snmpd.php in Unitrends Enterprise Backup 7.3.0 allows remote attackers to bypass authentication by setting the auth para
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %unitrends · enterprise backup2 мая 2014 г.
- CVE-2017-728223Наблюдать
An issue was discovered in Unitrends Enterprise Backup before 9.1.1.
СредняяCVSS 5,5Эксплойта нетEPSS 4 %unitrends · enterprise backup19 апр. 2017 г.