CVE-2021-43038

HIGH

Kaseya Unitrends Backup <10.5.5 - Privilege Escalation

Title source: llm
STIX 2.1

Description

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The wguest account could execute commands by injecting into PostgreSQL trigger functions. This allowed privilege escalation from the wguest user to the postgres user.

Scores

CVSS v3 8.8
EPSS 0.0223
EPSS Percentile 80.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-74
Status published
Products (1)
kaseya/unitrends_backup 10.0 - 10.5.5
Published Dec 06, 2021
Tracked Since Feb 18, 2026