Vulnerability record · CVE-2017-12478 · published 7 August 2017
CVE-2017-12478: Unitrends Backup api/storage auth bypass leads to root command execution
Kaseya · Unitrends Backup
The api/storage web interface in Unitrends Backup before 10.0.0 fails to validate an input parameter, allowing authentication to be bypassed. Because the flaw leads to arbitrary command execution as root, an unauthenticated network attacker can fully compromise the backup server.
Description
It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of its input parameters was not validated. A remote attacker could use this flaw to bypass authentication and execute arbitrary commands with root privilege on the target system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote root command execution with public exploit code and a very high EPSS score makes this an urgent patching target.
What it is
The api/storage web interface in Unitrends Backup before 10.0.0 fails to validate an input parameter, allowing authentication to be bypassed. Because the flaw leads to arbitrary command execution as root, an unauthenticated network attacker can fully compromise the backup server.
Impact
An attacker gains root-level command execution on the Unitrends Backup host, enabling full control of the system and any data or credentials it holds.
Attack surface
Reachable over the network through the api/storage web interface; the CVSS vector (AV:N/PR:N/UI:N) indicates no authentication or user interaction is required.
Exploitation
Public exploit code exists in Exploit-DB (references 43030 and 45559), and EPSS is very high at 0.783 (99.6th percentile), though the CVE is not listed in CISA KEV.
What to do
- Upgrade Unitrends Backup to version 10.0.0 or later, which the vendor advisory states resolves the issue.
- If immediate patching is not possible, restrict network access to the api/storage interface to trusted management hosts only.
- Place the backup server behind a firewall or VPN and avoid exposing its web interface to the internet.
- Audit the host for signs of compromise and rotate credentials for accounts and systems the backup server can reach.
Detection
- Review web server and application logs for unusual or malformed requests to the api/storage endpoint.
- Monitor for unexpected child processes spawned by the Unitrends Backup web service, especially shell or command interpreters.
- Alert on new outbound connections or authentication events originating from the backup server that deviate from its normal baseline.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.unitrends.com/UnitrendsBackup/s/article/000005756 | Vendor Advisory |
| https://www.exploit-db.com/exploits/43030/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/45559/ | ExploitThird Party AdvisoryVDB Entry |
| https://support.unitrends.com/UnitrendsBackup/s/article/000005756 | Vendor Advisory |
| https://www.exploit-db.com/exploits/43030/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/45559/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2017-12478 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-12478), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.