Rhino Security Labs

Unitrends Enterprise Backup Privilege Escalation in Token Cookie
[CVE-2017-7279]

Vulnerability Details

CVSS Rating: 9.8 (critical)

CVE-2017-7279

Disclosing Company: Rhino Security Labs

Date: 04/12/2017

Status: Published

Affected software/version:
Unitrends Enterprise Backup Web Server < 9.0.0

CVSS Metrics

CVSS Rating (version 3.0)

9.8 (Critical)

Impact Score

Exploitability Score

5.9

3.9

Attack Vector

Network

Attack Complexity (AC)Low Privileges Required (PR)None User Interaction (UI)None Scope (S)Unchanged

Confidentiality (C)High Integrity (I)High Availability (A)High