CVE-2021-43040: High severity unitrends backup vulnerability
Published Dec 6, 2021
·Updated
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The privileged vaultServer could be leveraged to create arbitrary writable files, leading to privilege escalation.
Affected Software
1 affected component
Kaseya Unitrends Backup>=10.0<10.5.5
Event History
Dec 6, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-43040?
CVE-2021-43040 has been classified as a high severity vulnerability due to the potential for privilege escalation.
2
How do I fix CVE-2021-43040?
To remediate CVE-2021-43040, upgrade your Kaseya Unitrends Backup Appliance to version 10.5.5 or later.
3
What are the consequences of exploiting CVE-2021-43040?
Exploiting CVE-2021-43040 allows an attacker to create arbitrary writable files, leading to unauthorized access and privilege escalation.
4
Which versions of Kaseya Unitrends Backup are affected by CVE-2021-43040?
Kaseya Unitrends Backup versions prior to 10.5.5 are affected by CVE-2021-43040.
5
Is there a workaround for CVE-2021-43040?
There are no recommended workarounds for CVE-2021-43040, so upgrading is the advised course of action.