CVE-2017-7279

CRITICAL

Unitrends Enterprise Backup <9.0.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" cookie issued at login.

Scores

CVSS v3 9.8
EPSS 0.0446
EPSS Percentile 89.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-565
Status published
Products (1)
unitrends/enterprise_backup < 8.2.0-8
Published Apr 12, 2017
Tracked Since Feb 18, 2026