Rhino Security Labs

Unitrends Enterprise Backup Remote Code Execution in systems.php File
[CVE-2017-7280]

Vulnerability Details

CVSS Rating: 9.8 (critical)

CVE-2017-7280

Disclosing Company: Rhino Security Labs

Date: 04/12/2017

Status: Published

Affected software/version:
Unitrends Enterprise Backup < 9.0.0

Disclosure

CVSS Metrics

CVSS Rating (version 3.0)

9.8 (Critical)

Impact Score

Exploitability Score

5.9

3.9

Attack Vector

Network

Attack Complexity (AC)Low Privileges Required (PR)None User Interaction (UI)None Scope (S)Unchanged

Confidentiality (C)High Integrity (I)High Availability (A)High