Known Vulnerabilities for products from Unitrends
Listed below are 11 of the newest known vulnerabilities associated with the vendor "Unitrends".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-8427 json | In Unitrends Backup before 10.4.1, an HTTP request parameter was not properly sanitized, allowing for SQL injection that resu... | 9.8 - CRITICAL | 2020-02-17 | 2022-01-01 |
| CVE-2018-6329 json | It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL inject... | 9.8 - CRITICAL | 2018-03-14 | 2019-03-07 |
| CVE-2018-6328 json | It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which ... | 9.8 - CRITICAL | 2018-03-14 | 2021-12-06 |
| CVE-2017-7284 json | An attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api/includes/users... | Not Provided | 2017-04-12 | 2025-04-20 |
| CVE-2017-7283 json | An authenticated user of Unitrends Enterprise Backup before 9.1.2 can execute arbitrary OS commands by sending a specially cr... | Not Provided | 2017-04-20 | 2025-04-20 |
| CVE-2017-7282 json | An issue was discovered in Unitrends Enterprise Backup before 9.1.1. The function downloadFile in api/includes/restore.php bl... | Not Provided | 2017-04-20 | 2025-04-20 |
| CVE-2017-7281 json | An issue was discovered in Unitrends Enterprise Backup before 9.1.2. A lack of sanitization of user input in the createReport... | Not Provided | 2017-04-12 | 2025-04-20 |
| CVE-2017-7280 json | An issue was discovered in api/includes/systems.php in Unitrends Enterprise Backup before 9.0.0. User input is not properly f... | Not Provided | 2017-04-12 | 2025-04-20 |
| CVE-2017-7279 json | An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying ... | Not Provided | 2017-04-12 | 2025-04-20 |
| CVE-2014-3139 json | recoveryconsole/bpl/snmpd.php in Unitrends Enterprise Backup 7.3.0 allows remote attackers to bypass authentication by settin... | Not Provided | 2014-05-02 | 2026-05-06 |
| CVE-2014-3008 json | Unitrends Enterprise Backup 7.3.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in... | Not Provided | 2014-04-28 | 2026-05-06 |
Known software with vulnerabilities from Unitrends
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Unitrends | Backup | 1.7.1h |
| Application | Unitrends | Enterprise Backup | 7.3.0 |