PT-2017-12565 · Unitrends · Unitrends Backup
Published
2017-08-07
·
Updated
2021-12-06
·
CVE-2017-12479
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Unitrends Backup versions prior to 10.0.0
Description
An issue in the session logic allowed using the
LOGDIR environment variable during a web session to elevate an existing low-privilege user to root privileges. A remote attacker with existing low-privilege credentials could then execute arbitrary commands with root privileges.Recommendations
For versions prior to 10.0.0, update to version 10.0.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the
LOGDIR environment variable to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Unitrends Backup