📦

backup

Vendor: unitrends

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 1 Remote Access
Total CVEs 2 Total Indexed
Avg. EPSS 39.67% Exploit Prob.
Latest CVE CVE-2020-8427 Feb 17

Security Vulnerability Index

Page 1 / 1
9.8 CVSS

In Unitrends Backup before 10.4.1, an HTTP request parameter was not properly sanitized, allowing for SQL injection that resulted in an authentication bypass.

EPSS: 0.35%
9.8 CVSS
CVE-2018-6329
RCE Exploit Found

It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL injection, allowing a remote attacker to place a privilege escalation exploit on the target system and subsequently execute arbitrary commands.

EPSS: 78.99%