Vulnerability record · CVE-2017-12477 · published 7 August 2017
CVE-2017-12477: Unitrends Backup bpserverd authentication bypass allows root command execution
Kaseya · Unitrends Backup
The bpserverd proprietary protocol in Unitrends Backup before 10.0.0, invoked through xinetd, can have its authentication bypassed. A remote attacker can exploit this to execute arbitrary commands with root privilege on the target system. The flaw is an improper authentication issue (CWE-287) with a critical CVSS score of 9.8.
Description
It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xinetd, has an issue in which its authentication can be bypassed. A remote attacker could use this issue to execute arbitrary commands with root privilege on the target system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, public exploit available, and very high EPSS probability make this an urgent risk for unpatched Unitrends Backup systems.
What it is
The bpserverd proprietary protocol in Unitrends Backup before 10.0.0, invoked through xinetd, can have its authentication bypassed. A remote attacker can exploit this to execute arbitrary commands with root privilege on the target system. The flaw is an improper authentication issue (CWE-287) with a critical CVSS score of 9.8.
Impact
An unauthenticated remote attacker gains root-level command execution on the Unitrends Backup server, leading to full system compromise. This can result in data theft, ransomware deployment, or use of the backup server as a pivot point into the network.
Attack surface
The vulnerability is reachable over the network via the bpserverd protocol, which is exposed through xinetd. No authentication or user interaction is required, as indicated by the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
A public exploit exists (Exploit-DB 43031), and EPSS indicates a high probability of exploitation (0.68217, 99.294th percentile). The CVE is not listed in CISA KEV, and no ransomware groups are documented as using it.
What to do
- Upgrade Unitrends Backup to version 10.0.0 or later as recommended by the vendor advisory.
- Restrict network access to the bpserverd service (e.g., via firewall rules) to trusted hosts only.
- Disable or remove the xinetd service for bpserverd if it is not required.
- Monitor for and investigate any unexpected root-level command execution or process creation on Unitrends Backup servers.
Detection
- Monitor network traffic for connections to the bpserverd port (default unknown; check xinetd configuration) from untrusted sources.
- Audit system logs for authentication bypass attempts or anomalous command execution with root privileges.
- Use endpoint detection to alert on suspicious child processes spawned by bpserverd or xinetd.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.unitrends.com/UnitrendsBackup/s/article/000005755 | Vendor Advisory |
| https://www.exploit-db.com/exploits/43031/ | ExploitThird Party AdvisoryVDB Entry |
| https://support.unitrends.com/UnitrendsBackup/s/article/000005755 | Vendor Advisory |
| https://www.exploit-db.com/exploits/43031/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2017-12477 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-12477), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.