← Vulnerability feed

Vulnerability record · CVE-2017-12478 · published 7 August 2017

CVE-2017-12478: Unitrends Backup api/storage auth bypass leads to root command execution

Kaseya · Unitrends Backup

The api/storage web interface in Unitrends Backup before 10.0.0 fails to validate an input parameter, allowing authentication to be bypassed. Because the flaw leads to arbitrary command execution as root, an unauthenticated network attacker can fully compromise the backup server.

9.8 CVSS 3.1 Critical EPSS 78% · top 0.4% CWE-287 · Improper authentication
9.8CVSS 3.1 base score, v2 10.0
78%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of its input parameters was not validated. A remote attacker could use this flaw to bypass authentication and execute arbitrary commands with root privilege on the target system.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote root command execution with public exploit code and a very high EPSS score makes this an urgent patching target.

What it is

The api/storage web interface in Unitrends Backup before 10.0.0 fails to validate an input parameter, allowing authentication to be bypassed. Because the flaw leads to arbitrary command execution as root, an unauthenticated network attacker can fully compromise the backup server.

Impact

An attacker gains root-level command execution on the Unitrends Backup host, enabling full control of the system and any data or credentials it holds.

Attack surface

Reachable over the network through the api/storage web interface; the CVSS vector (AV:N/PR:N/UI:N) indicates no authentication or user interaction is required.

Exploitation

Public exploit code exists in Exploit-DB (references 43030 and 45559), and EPSS is very high at 0.783 (99.6th percentile), though the CVE is not listed in CISA KEV.

What to do

  • Upgrade Unitrends Backup to version 10.0.0 or later, which the vendor advisory states resolves the issue.
  • If immediate patching is not possible, restrict network access to the api/storage interface to trusted management hosts only.
  • Place the backup server behind a firewall or VPN and avoid exposing its web interface to the internet.
  • Audit the host for signs of compromise and rotate credentials for accounts and systems the backup server can reach.

Detection

  • Review web server and application logs for unusual or malformed requests to the api/storage endpoint.
  • Monitor for unexpected child processes spawned by the Unitrends Backup web service, especially shell or command interpreters.
  • Alert on new outbound connections or authentication events originating from the backup server that deviate from its normal baseline.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-12478 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-40386Kaseya unitrends backup vulnerabilityKaseya Unitrends Client/Agent through 10.5,5 allows remote attackers to execute arbitrary code.EPSS 1.9%9.8CVE-2021-43033Kaseya unitrends backup os command injection vulnerabilityAn issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Multiple functions in the bpserverd daemon were vulnerable to arbitrary r…EPSS 6.0%9.8CVE-2021-43035Kaseya unitrends backup sql injection vulnerabilityAn issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Two unauthenticated SQL injection vulnerabilities were discovered, allowi…EPSS 3.3%9.8CVE-2021-43036Kaseya unitrends backup weak password requirements vulnerabilityAn issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The password for the PostgreSQL wguest account is weak.EPSS 1.9%9.8CVE-2021-43042Kaseya unitrends backup classic buffer overflow vulnerabilityAn issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A buffer overflow existed in the vaultServer component. This was exploita…EPSS 2.9%9.8CVE-2021-43044Kaseya unitrends backup hard-coded credentials vulnerabilityAn issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The SNMP daemon was configured with a weak default community.EPSS 1.9%9.8CVE-2018-6328Unitrends Backup authentication bypass leads to command injectionUnitrends Backup before 10.1.0 exposes a user interface vulnerable to an authentication bypass, allowing an unauthenticated user to reach the /api/ho…EPSS 64%analysed9.8CVE-2017-12477Unitrends Backup bpserverd authentication bypass allows root command executionThe bpserverd proprietary protocol in Unitrends Backup before 10.0.0, invoked through xinetd, can have its authentication bypassed. A remote attacker…EPSS 68%analysed

Source: NIST National Vulnerability Database (record CVE-2017-12478), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.