Privilege Escalation Vulnerability in Kaseya Unitrends Backup Software
CVE-2021-40385

8.8HIGH

Key Information:

Vendor

Kaseya

Vendor
CVE Published:
1 September 2021

What is CVE-2021-40385?

A security flaw exists in the Kaseya Unitrends Backup Software, where a read-only user can escalate their privileges to gain admin access. This vulnerability could allow unauthorized users to modify settings, access sensitive data, and perform administrative tasks without appropriate permissions. Organizations using affected versions should promptly apply recommended updates to mitigate potential risks.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.