← Vulnerability feed

Vulnerability record · CVE-2017-12477 · published 7 August 2017

CVE-2017-12477: Unitrends Backup bpserverd authentication bypass allows root command execution

Kaseya · Unitrends Backup

The bpserverd proprietary protocol in Unitrends Backup before 10.0.0, invoked through xinetd, can have its authentication bypassed. A remote attacker can exploit this to execute arbitrary commands with root privilege on the target system. The flaw is an improper authentication issue (CWE-287) with a critical CVSS score of 9.8.

9.8 CVSS 3.1 Critical EPSS 68% · top 0.7% CWE-287 · Improper authentication
9.8CVSS 3.1 base score, v2 10.0
68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xinetd, has an issue in which its authentication can be bypassed. A remote attacker could use this issue to execute arbitrary commands with root privilege on the target system.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8, public exploit available, and very high EPSS probability make this an urgent risk for unpatched Unitrends Backup systems.

What it is

The bpserverd proprietary protocol in Unitrends Backup before 10.0.0, invoked through xinetd, can have its authentication bypassed. A remote attacker can exploit this to execute arbitrary commands with root privilege on the target system. The flaw is an improper authentication issue (CWE-287) with a critical CVSS score of 9.8.

Impact

An unauthenticated remote attacker gains root-level command execution on the Unitrends Backup server, leading to full system compromise. This can result in data theft, ransomware deployment, or use of the backup server as a pivot point into the network.

Attack surface

The vulnerability is reachable over the network via the bpserverd protocol, which is exposed through xinetd. No authentication or user interaction is required, as indicated by the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

A public exploit exists (Exploit-DB 43031), and EPSS indicates a high probability of exploitation (0.68217, 99.294th percentile). The CVE is not listed in CISA KEV, and no ransomware groups are documented as using it.

What to do

  • Upgrade Unitrends Backup to version 10.0.0 or later as recommended by the vendor advisory.
  • Restrict network access to the bpserverd service (e.g., via firewall rules) to trusted hosts only.
  • Disable or remove the xinetd service for bpserverd if it is not required.
  • Monitor for and investigate any unexpected root-level command execution or process creation on Unitrends Backup servers.

Detection

  • Monitor network traffic for connections to the bpserverd port (default unknown; check xinetd configuration) from untrusted sources.
  • Audit system logs for authentication bypass attempts or anomalous command execution with root privileges.
  • Use endpoint detection to alert on suspicious child processes spawned by bpserverd or xinetd.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-12477 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-40386Kaseya unitrends backup vulnerabilityKaseya Unitrends Client/Agent through 10.5,5 allows remote attackers to execute arbitrary code.EPSS 1.9%9.8CVE-2021-43033Kaseya unitrends backup os command injection vulnerabilityAn issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Multiple functions in the bpserverd daemon were vulnerable to arbitrary r…EPSS 6.0%9.8CVE-2021-43035Kaseya unitrends backup sql injection vulnerabilityAn issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Two unauthenticated SQL injection vulnerabilities were discovered, allowi…EPSS 3.3%9.8CVE-2021-43036Kaseya unitrends backup weak password requirements vulnerabilityAn issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The password for the PostgreSQL wguest account is weak.EPSS 1.9%9.8CVE-2021-43042Kaseya unitrends backup classic buffer overflow vulnerabilityAn issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A buffer overflow existed in the vaultServer component. This was exploita…EPSS 2.9%9.8CVE-2021-43044Kaseya unitrends backup hard-coded credentials vulnerabilityAn issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The SNMP daemon was configured with a weak default community.EPSS 1.9%9.8CVE-2018-6328Unitrends Backup authentication bypass leads to command injectionUnitrends Backup before 10.1.0 exposes a user interface vulnerable to an authentication bypass, allowing an unauthenticated user to reach the /api/ho…EPSS 64%analysed9.8CVE-2017-12478Unitrends Backup api/storage auth bypass leads to root command executionThe api/storage web interface in Unitrends Backup before 10.0.0 fails to validate an input parameter, allowing authentication to be bypassed. Because…EPSS 78%analysed

Source: NIST National Vulnerability Database (record CVE-2017-12477), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.