← Vulnerability feed

Vulnerability record · CVE-2021-43033 · published 6 December 2021

CVE-2021-43033: Kaseya unitrends backup os command injection vulnerability

Kaseya · Unitrends Backup

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Multiple functions in the bpserverd daemon were vulnerable to arbitrary remote code execution as root. The vulnerability was caused by untrusted input (received by the server) being passed to system calls.

9.8 CVSS 3.1 Critical EPSS 6.0% · top 6.9% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 10.0
6.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Multiple functions in the bpserverd daemon were vulnerable to arbitrary remote code execution as root. The vulnerability was caused by untrusted input (received by the server) being passed to system calls.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-43033 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-40386Kaseya unitrends backup vulnerabilityKaseya Unitrends Client/Agent through 10.5,5 allows remote attackers to execute arbitrary code.EPSS 1.9%9.8CVE-2021-43035Kaseya unitrends backup sql injection vulnerabilityAn issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Two unauthenticated SQL injection vulnerabilities were discovered, allowi…EPSS 3.3%9.8CVE-2021-43036Kaseya unitrends backup weak password requirements vulnerabilityAn issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The password for the PostgreSQL wguest account is weak.EPSS 1.9%9.8CVE-2021-43042Kaseya unitrends backup classic buffer overflow vulnerabilityAn issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A buffer overflow existed in the vaultServer component. This was exploita…EPSS 2.9%9.8CVE-2021-43044Kaseya unitrends backup hard-coded credentials vulnerabilityAn issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The SNMP daemon was configured with a weak default community.EPSS 1.9%9.8CVE-2018-6328Unitrends Backup authentication bypass leads to command injectionUnitrends Backup before 10.1.0 exposes a user interface vulnerable to an authentication bypass, allowing an unauthenticated user to reach the /api/ho…EPSS 64%analysed9.8CVE-2017-12477Unitrends Backup bpserverd authentication bypass allows root command executionThe bpserverd proprietary protocol in Unitrends Backup before 10.0.0, invoked through xinetd, can have its authentication bypassed. A remote attacker…EPSS 68%analysed9.8CVE-2017-12478Unitrends Backup api/storage auth bypass leads to root command executionThe api/storage web interface in Unitrends Backup before 10.0.0 fails to validate an input parameter, allowing authentication to be bypassed. Because…EPSS 78%analysed

Source: NIST National Vulnerability Database (record CVE-2021-43033), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.