← Vulnerability feed

Vulnerability record · CVE-2017-7284 · published 12 April 2017

CVE-2017-7284: Unitrends enterprise backup improper authentication vulnerability

Unitrends · Enterprise Backup

An attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api/includes/users.php to change the password of the logged in account without knowing the current password. This allows for an account takeover.

8.8 CVSS 3.0 High EPSS 2.7% · top 14.9% CWE-287 · Improper authentication
8.8CVSS 3.0 base score, v2 6.5
2.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api/includes/users.php to change the password of the logged in account without knowing the current password. This allows for an account takeover.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-7284 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2014-3008Unitrends enterprise backup os command injection vulnerabilityUnitrends Enterprise Backup 7.3.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the comm parameter to r…EPSS 7.0%9.8CVE-2017-7279Unitrends enterprise backup reliance on cookies without validation vulnerabilityAn unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" cookie issue…EPSS 4.4%9.8CVE-2017-7280Unitrends enterprise backup improper input validation vulnerabilityAn issue was discovered in api/includes/systems.php in Unitrends Enterprise Backup before 9.0.0. User input is not properly filtered before being sen…EPSS 6.2%8.8CVE-2017-7283Unitrends enterprise backup improper input validation vulnerabilityAn authenticated user of Unitrends Enterprise Backup before 9.1.2 can execute arbitrary OS commands by sending a specially crafted filename to the /a…EPSS 4.3%8.8CVE-2017-7281Unitrends enterprise backup unrestricted file upload vulnerabilityAn issue was discovered in Unitrends Enterprise Backup before 9.1.2. A lack of sanitization of user input in the createReportName and saveReport func…EPSS 4.3%7.5CVE-2014-3139Unitrends enterprise backup improper authentication vulnerabilityrecoveryconsole/bpl/snmpd.php in Unitrends Enterprise Backup 7.3.0 allows remote attackers to bypass authentication by setting the auth parameter to …EPSS 3.3%5.5CVE-2017-7282Unitrends enterprise backup information exposure vulnerabilityAn issue was discovered in Unitrends Enterprise Backup before 9.1.1. The function downloadFile in api/includes/restore.php blindly accepts any filena…EPSS 4.3%7.5CVE-2026-42018JFrog Artifactory improper authentication leaks anonymous tokenJFrog Artifactory can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled. Because the token …KEVEPSS 9.8%analysed

Source: NIST National Vulnerability Database (record CVE-2017-7284), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.