CVE-2018-6328 EXPLOIT
9.8
CRITICAL · CVSS 3.0 · EPSS 64.4% (pctl 99)
Patch early
A public exploit exists.
Description
It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unauthenticated user to inject arbitrary commands into its /api/hosts parameters using backquotes.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 64.37% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-287 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-03-14 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| kaseya | unitrends backup |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Unitrends UEB - HTTP API Remote Code Execution (Metasploit) | 2018-10-08 |
| exploit-db | Unitrends UEB 10.0 - Root Remote Code Execution | 2018-03-16 |
References
- https://support.unitrends.com/UnitrendsBackup/s/article/000001150
- https://support.unitrends.com/UnitrendsBackup/s/article/000006002
- https://www.exploit-db.com/exploits/44297/
- https://www.exploit-db.com/exploits/45559/
- https://support.unitrends.com/UnitrendsBackup/s/article/000001150
- https://support.unitrends.com/UnitrendsBackup/s/article/000006002
- https://www.exploit-db.com/exploits/44297/
- https://www.exploit-db.com/exploits/45559/
→ the Explorer · watch your stack · NVD