CVE-2021-43043: Medium severity unitrends backup vulnerability
Published Dec 6, 2021
·Updated
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The apache user could read arbitrary files such as /etc/shadow by abusing an insecure Sudo rule.
Affected Software
1 affected component
Kaseya Unitrends Backup>=10.0<10.5.5
Event History
Dec 6, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-43043?
CVE-2021-43043 has a medium severity rating due to the potential for unauthorized access to sensitive files.
2
How do I fix CVE-2021-43043?
To fix CVE-2021-43043, upgrade your Kaseya Unitrends Backup Appliance to version 10.5.5 or later.
3
What systems are affected by CVE-2021-43043?
CVE-2021-43043 affects Kaseya Unitrends Backup Appliance versions prior to 10.5.5.
4
What is the impact of CVE-2021-43043?
The impact of CVE-2021-43043 is that the apache user can read arbitrary files, potentially exposing sensitive information.
5
Is there a workaround for CVE-2021-43043?
There are no specific workarounds for CVE-2021-43043; updating to the latest version is the recommended action.