An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A crafted HTTP request could induce a format string vulnerability in the privileged vaultServer application.
References
Link | Resource |
---|---|
https://helpdesk.kaseya.com/hc/en-gb/articles/4412762258961 | Vendor Advisory |
https://www.cyberonesecurity.com/blog/exploiting-kaseya-unitrends-backup-appliance-part-1 | Exploit Third Party Advisory |
https://www.cyberonesecurity.com/blog/exploiting-kaseya-unitrends-backup-appliance-part-2 | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2021-12-06 04:15
Updated : 2024-02-28 18:48
NVD link : CVE-2021-43041
Mitre link : CVE-2021-43041
CVE.ORG link : CVE-2021-43041
JSON object : View
Products Affected
kaseya
- unitrends_backup
CWE
CWE-134
Use of Externally-Controlled Format String