Vulnerability record · CVE-2018-6328 · published 14 March 2018
CVE-2018-6328: Unitrends Backup authentication bypass leads to command injection
Kaseya · Unitrends Backup
Unitrends Backup before 10.1.0 exposes a user interface vulnerable to an authentication bypass, allowing an unauthenticated user to reach the /api/hosts endpoint. Because the parameters there are passed to a shell without sanitization, backquotes can be used to inject arbitrary commands. This is a critical pre-auth remote code execution flaw in a backup product that typically holds privileged credentials and access to protected data.
Description
It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unauthenticated user to inject arbitrary commands into its /api/hosts parameters using backquotes.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityPre-authentication remote command execution with a CVSS score of 9.8, public exploit code and very high EPSS probability makes this an urgent patch target.
What it is
Unitrends Backup before 10.1.0 exposes a user interface vulnerable to an authentication bypass, allowing an unauthenticated user to reach the /api/hosts endpoint. Because the parameters there are passed to a shell without sanitization, backquotes can be used to inject arbitrary commands. This is a critical pre-auth remote code execution flaw in a backup product that typically holds privileged credentials and access to protected data.
Impact
An unauthenticated attacker can execute arbitrary commands on the backup server, likely with the privileges of the web service, leading to full compromise of the host and any data or credentials it manages.
Attack surface
Reachable over the network via the Unitrends Backup web interface and its /api/hosts API; the CVSS vector shows no privileges or user interaction required. No authentication is needed because the flaw is itself an authentication bypass.
Exploitation
Not listed in CISA KEV, but public exploit code exists in Exploit-DB (44297, 45559) and EPSS is high at 0.64 (99th percentile), indicating elevated likelihood of exploitation.
What to do
- Upgrade Unitrends Backup to 10.1.0 or later as directed by the vendor advisories.
- If immediate patching is not possible, restrict network access to the Unitrends Backup web interface and API to trusted management networks only.
- Place the appliance behind a firewall or VPN and block direct internet exposure of the UI and /api endpoints.
- Monitor and rotate any credentials or secrets stored on or accessible from the backup server, since command execution may expose them.
- Review vendor advisories 000001150 and 000006002 for any additional hardening guidance.
Detection
- Inspect web and API logs for requests to /api/hosts containing backquotes or shell metacharacters.
- Alert on unexpected child processes spawned by the Unitrends web service (for example shells or command interpreters).
- Monitor for anomalous outbound connections or new listening services on the backup server.
- Audit authentication logs for access to the UI or API without a valid session preceding command activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.unitrends.com/UnitrendsBackup/s/article/000001150 | Vendor Advisory |
| https://support.unitrends.com/UnitrendsBackup/s/article/000006002 | Vendor Advisory |
| https://www.exploit-db.com/exploits/44297/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/45559/ | ExploitThird Party AdvisoryVDB Entry |
| https://support.unitrends.com/UnitrendsBackup/s/article/000001150 | Vendor Advisory |
| https://support.unitrends.com/UnitrendsBackup/s/article/000006002 | Vendor Advisory |
| https://www.exploit-db.com/exploits/44297/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/45559/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2018-6328 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-6328), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.