CVE-2017-7279: Critical severity Unitrends Enterprise Backup vulnerability
Published Apr 12, 2017
·Updated
An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" cookie issued at login.
Affected Software
1 affected component
Unitrends Enterprise Backup<=8.2.0-8
Event History
Apr 12, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:59 PM
DescriptionSeverityWeaknessAffected Software
Jun 19, 58461
Event
12:26 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-7279?
CVE-2017-7279 is classified as a critical vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2017-7279?
To fix CVE-2017-7279, upgrade to Unitrends Enterprise Backup version 9.0.0 or later.
3
Who is affected by CVE-2017-7279?
CVE-2017-7279 affects unprivileged users of Unitrends Enterprise Backup versions prior to 9.0.0.
4
What type of attack does CVE-2017-7279 enable?
CVE-2017-7279 enables an unprivileged user to escalate their privileges to root.
5
Can CVE-2017-7279 be exploited remotely?
Yes, CVE-2017-7279 can be exploited remotely by manipulating the 'token' cookie during login.