PT-2017-17635 · Unitrends · Unitrends Enterprise Backup

Publicado

2017-04-12

·

Atualizado

2019-10-03

·

CVE-2017-7284

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Unitrends Enterprise Backup versions prior to 9.1.2
Description The issue allows an attacker who has hijacked a Unitrends Enterprise Backup web server session to change the password of the logged-in account without knowing the current password, enabling account takeover. The attacker can leverage the "api/includes/users.php" endpoint to achieve this.
Recommendations For versions prior to 9.1.2, update to version 9.1.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the "api/includes/users.php" endpoint until a patch is applied.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-7284

Produtos afetados

Unitrends Enterprise Backup