Vulnerability index

Browse CVEs

32 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unitrends Backup CRITICAL 9.8
CVE-2021-40386

Kaseya Unitrends Client/Agent through 10.5,5 allows remote attackers to execute arbitrary code.

Fix: after 10.5.5
Fix from $2,300 2022-04-15
Unitrends Backup CRITICAL 9.8
CVE-2021-43033EPSS 6%

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Multiple functions in the bpserverd daemon were vulnerable to arbitrary r…

Fix: 10.5.5+
Fix from $2,300 2021-12-06
Unitrends Backup CRITICAL 9.8
CVE-2021-43035

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Two unauthenticated SQL injection vulnerabilities were discovered, allowi…

Fix: 10.5.5+
Fix from $2,300 2021-12-06
Unitrends Backup CRITICAL 9.8
CVE-2021-43036

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The password for the PostgreSQL wguest account is weak.

Fix: 10.5.5+
Fix from $2,300 2021-12-06
Unitrends Backup CRITICAL 9.8
CVE-2021-43042

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A buffer overflow existed in the vaultServer component. This was exploita…

Fix: 10.5.5+
Fix from $2,300 2021-12-06
Unitrends Backup CRITICAL 9.8
CVE-2021-43044

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The SNMP daemon was configured with a weak default community.

Fix: 10.5.5+
Fix from $2,300 2021-12-06
Unitrends Backup HIGH 8.8
CVE-2021-43038

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The wguest account could execute commands by injecting into PostgreSQL tr…

Fix: 10.5.5+
Fix from $1,950 2021-12-06
Unitrends Backup HIGH 8.8
CVE-2021-43040

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The privileged vaultServer could be leveraged to create arbitrary writabl…

Fix: 10.5.5+
Fix from $1,950 2021-12-06
Unitrends Backup HIGH 8.8
CVE-2021-43041

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A crafted HTTP request could induce a format string vulnerability in the …

Fix: 10.5.5+
Fix from $1,950 2021-12-06
Unitrends Backup HIGH 7.8
CVE-2021-43034

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A world writable file allowed local users to execute arbitrary code as th…

Fix: 10.5.5+
Fix from $1,950 2021-12-06
Unitrends Backup HIGH 7.8
CVE-2021-43037

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Unitrends Windows agent was vulnerable to DLL injection and binary pl…

Fix: 10.5.5+
Fix from $1,950 2021-12-06
Unitrends Backup MEDIUM 6.5
CVE-2021-43039

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Samba file sharing service allowed anonymous read/write access.

Fix: 10.5.5+
Fix from $1,600 2021-12-06
Unitrends Backup MEDIUM 6.5
CVE-2021-43043

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The apache user could read arbitrary files such as /etc/shadow by abusing…

Fix: 10.5.5+
Fix from $1,600 2021-12-06
Unitrends Backup Software HIGH 8.8
CVE-2021-40385

An issue was discovered in the server software in Kaseya Unitrends Backup Software before 10.5.5-2. There is a privilege escalation from read-only us…

Fix: 10.5.5-2+
Fix from $1,950 2021-09-01
Unitrends Backup Software HIGH 8.8
CVE-2021-40387

An issue was discovered in the server software in Kaseya Unitrends Backup Software before 10.5.5-2. There is authenticated remote code execution.

Fix: 10.5.5-2+
Fix from $1,950 2021-09-01
Vsa Agent CRITICAL 9.8
CVE-2021-30116 KEVEPSS 86%

Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page …

Fix: 9.5.0.24 / 9.5.7a+
Fix from $2,300 2021-07-09
Vsa CRITICAL 9.8
CVE-2021-30118EPSS 60%

An attacker can upload files with the privilege of the Web Server process for Kaseya VSA Unified Remote Monitoring & Management (RMM) 9.5.4.2149 and …

Fix: 9.5.5+
Fix from $2,300 2021-07-09
Vsa HIGH 8.8
CVE-2021-30117EPSS 72%

The API call /InstallTab/exportFldr.asp is vulnerable to a semi-authenticated boolean-based blind SQL injection in the parameter fldrId. Detailed des…

Fix: 9.5.6+
Fix from $1,950 2021-07-09
Vsa HIGH 7.5
CVE-2021-30120EPSS 6%

Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of serv…

Fix: after 9.5.6
Fix from $1,950 2021-07-09
Vsa HIGH 7.5
CVE-2021-30201EPSS 25%

The API /vsaWS/KaseyaWS.asmx can be used to submit XML to the system. When this XML is processed (external) entities are insecurely processed and fet…

Fix: 9.5.6+
Fix from $1,950 2021-07-09
Vsa MEDIUM 6.5
CVE-2021-30121

Semi-authenticated local file inclusion The contents of arbitrary files can be returned by the webserver Example request: `https://x.x.x.x/KLC/js/Kas…

Fix: 9.5.6+
Fix from $1,600 2021-07-09
Vsa MEDIUM 5.4
CVE-2021-30119EPSS 53%

Authenticated reflective XSS in HelpDeskTab/rcResults.asp The parameter result of /HelpDeskTab/rcResults.asp is insecurely returned in the requested …

Fix: 9.5.7+
Fix from $1,600 2021-07-09
Virtual System Administrator CRITICAL 9.8
CVE-2015-6922EPSS 82%

Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before 9.1.0.9 does not properly req…

Fix: 7.0.0.33 / 8.0.0.23+
Fix from $2,300 2020-02-17
Virtual System Administrator HIGH 8.8
CVE-2015-6589EPSS 14%

Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before 8.0.0.23, 9.0.0.0 before 9.0.…

Fix: 7.0.0.33 / 8.0.0.23+
Fix from $1,950 2020-02-13
Vsa MEDIUM 6.7
CVE-2019-14510

An issue was discovered in Kaseya VSA RMM through 9.5.0.22. When using the default configuration, the LAN Cache feature creates a local account FSAdm…

Fix: after 9.5.0.22
Fix from $1,600 2019-10-11
Virtual System Administrator HIGH 7.5
CVE-2019-15506

An issue was discovered in Kaseya Virtual System Administrator (VSA) through 9.4.0.37. It has a critical information disclosure vulnerability. An una…

Fix: after 9.4.0.37
Fix from $1,950 2019-08-26
Virtual System Administrator CRITICAL 9.8
CVE-2018-20753 KEVEPSS 29%

Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payload…

Fix: 9.3.0.35 / 9.4.0.36+
Fix from $2,300 2019-02-05
Virtual System Administrator HIGH 7.4
CVE-2017-12410

It is possible to exploit a Time of Check & Time of Use (TOCTOU) vulnerability by winning a race condition when Kaseya Virtual System Administrator a…

Fix: after 9.3.0.11
Fix from $1,950 2018-03-26
Unitrends Backup CRITICAL 9.8
CVE-2018-6328EPSS 65%

It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unau…

Fix: 10.1+
Fix from $2,300 2018-03-14
Unitrends Backup CRITICAL 9.8
CVE-2017-12477EPSS 68%

It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xinetd, has an issue in which it…

Fix: 10.0+
Fix from $2,300 2017-08-07