{"api_version":"1","generated_at":"2026-07-23T13:00:53+00:00","cve":"CVE-2021-43035","urls":{"html":"https://cve.report/CVE-2021-43035","api":"https://cve.report/api/cve/CVE-2021-43035.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-43035","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-43035"},"summary":{"title":"CVE-2021-43035","description":"An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Two unauthenticated SQL injection vulnerabilities were discovered, allowing arbitrary SQL queries to be injected and executed under the postgres superuser account. Remote code execution was possible, leading to full access to the postgres user account.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-12-06 04:15:00","updated_at":"2022-11-28 21:43:00"},"problem_types":["CWE-89"],"metrics":[],"references":[{"url":"https://www.cyberonesecurity.com/blog/exploiting-kaseya-unitrends-backup-appliance-part-1","name":"https://www.cyberonesecurity.com/blog/exploiting-kaseya-unitrends-backup-appliance-part-1","refsource":"MISC","tags":[],"title":"Exploiting Kaseya Unitrends Backup Appliance – Part 1 - CyberOne Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://helpdesk.kaseya.com/hc/en-gb/articles/4412762258961","name":"https://helpdesk.kaseya.com/hc/en-gb/articles/4412762258961","refsource":"MISC","tags":[],"title":"Security check","mime":"text/html","httpstatus":"403","archivestatus":"404"},{"url":"https://www.cyberonesecurity.com/blog/exploiting-kaseya-unitrends-backup-appliance-part-2","name":"https://www.cyberonesecurity.com/blog/exploiting-kaseya-unitrends-backup-appliance-part-2","refsource":"MISC","tags":[],"title":"Exploiting Kaseya Unitrends Backup Appliance – Part 2 - CyberOne Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-43035","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-43035","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"43035","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"kaseya","cpe5":"unitrends_backup","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-43035","qid":"376380","title":"Kaseya Unitrends Backup Appliance Multiple Vulnerabilities (4412762258961)"},{"cve":"CVE-2021-43035","qid":"730324","title":"Kaseya Unitrends Backup Appliance Multiple Vulnerabilities (4412762258961)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-43035","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Two unauthenticated SQL injection vulnerabilities were discovered, allowing arbitrary SQL queries to be injected and executed under the postgres superuser account. Remote code execution was possible, leading to full access to the postgres user account."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://helpdesk.kaseya.com/hc/en-gb/articles/4412762258961","url":"https://helpdesk.kaseya.com/hc/en-gb/articles/4412762258961"},{"refsource":"MISC","name":"https://www.cyberonesecurity.com/blog/exploiting-kaseya-unitrends-backup-appliance-part-1","url":"https://www.cyberonesecurity.com/blog/exploiting-kaseya-unitrends-backup-appliance-part-1"},{"refsource":"MISC","name":"https://www.cyberonesecurity.com/blog/exploiting-kaseya-unitrends-backup-appliance-part-2","url":"https://www.cyberonesecurity.com/blog/exploiting-kaseya-unitrends-backup-appliance-part-2"}]}},"nvd":{"publishedDate":"2021-12-06 04:15:00","lastModifiedDate":"2022-11-28 21:43:00","problem_types":["CWE-89"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:kaseya:unitrends_backup:*:*:*:*:*:*:*:*","versionStartIncluding":"10.0","versionEndExcluding":"10.5.5","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"43035","Ordinal":"219557","Title":"CVE-2021-43035","CVE":"CVE-2021-43035","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"43035","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}