CVE-2021-40385: High severity Kaseya Unitrends Backup Software vulnerability
Published Sep 1, 2021
·Updated
An issue was discovered in the server software in Kaseya Unitrends Backup Software before 10.5.5-2. There is a privilege escalation from read-only user to admin.
Affected Software
1 affected component
Kaseya Unitrends Backup Software<10.5.5-2
Event History
Sep 1, 2021
CVE Published
via MITRE·08:55 PM
Data Sourced
via MITRE·08:55 PM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-40385?
The severity of CVE-2021-40385 is critical with a CVSS score of 8.8.
2
How can I escalate privileges in Kaseya Unitrends Backup Software before 10.5.5-2?
There is a privilege escalation vulnerability in Kaseya Unitrends Backup Software before 10.5.5-2 that allows read-only users to become admins.