HIGH🇵🇱 Wersja polska

CVE-2014-3139

CVSS 7.5v2.0pub. 2014-05-02upd. 2026-05-06

recoveryconsole/bpl/snmpd.php in Unitrends Enterprise Backup 7.3.0 allows remote attackers to bypass authentication by setting the auth parameter to a certain string.

CVSS Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
  • Unitrends Enterprise Backup

    APP
    Unitrends
    7.3.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2017-7279CRITICAL9.8PL ✓same product

Privilege escalation przez manipulację cookie 'token' w Unitrends Enterprise Backup

CVE-2017-7280CRITICAL9.8PL ✓same product

RCE w Unitrends Enterprise Backup — niefiltrowane dane w popen()

CVE-2017-7283HIGH8.8same product

An authenticated user of Unitrends Enterprise Backup before 9.1.2 can execute arbitrary OS commands by sending...

CVE-2017-7281HIGH8.8same product

An issue was discovered in Unitrends Enterprise Backup before 9.1.2. A lack of sanitization of user input in t...

CVE-2017-7284HIGH8.8same product

An attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api...