Vulnerability Details CVE-2021-43040
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The privileged vaultServer could be leveraged to create arbitrary writable files, leading to privilege escalation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 72.3%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
Products affected by CVE-2021-43040
-
cpe:2.3:a:kaseya:unitrends_backup:10.0
-
cpe:2.3:a:kaseya:unitrends_backup:10.1
-
cpe:2.3:a:kaseya:unitrends_backup:10.1.1
-
cpe:2.3:a:kaseya:unitrends_backup:10.2
-
cpe:2.3:a:kaseya:unitrends_backup:10.2.1
-
cpe:2.3:a:kaseya:unitrends_backup:10.3.1
-
cpe:2.3:a:kaseya:unitrends_backup:10.3.10
-
cpe:2.3:a:kaseya:unitrends_backup:10.3.11
-
cpe:2.3:a:kaseya:unitrends_backup:10.3.2
-
cpe:2.3:a:kaseya:unitrends_backup:10.3.3
-
cpe:2.3:a:kaseya:unitrends_backup:10.3.4
-
cpe:2.3:a:kaseya:unitrends_backup:10.3.5
-
cpe:2.3:a:kaseya:unitrends_backup:10.3.6
-
cpe:2.3:a:kaseya:unitrends_backup:10.3.7
-
cpe:2.3:a:kaseya:unitrends_backup:10.3.8
-
cpe:2.3:a:kaseya:unitrends_backup:10.3.9
-
cpe:2.3:a:kaseya:unitrends_backup:10.4.0
-
cpe:2.3:a:kaseya:unitrends_backup:10.4.1
-
cpe:2.3:a:kaseya:unitrends_backup:10.4.10
-
cpe:2.3:a:kaseya:unitrends_backup:10.4.11
-
cpe:2.3:a:kaseya:unitrends_backup:10.4.2
-
cpe:2.3:a:kaseya:unitrends_backup:10.4.3
-
cpe:2.3:a:kaseya:unitrends_backup:10.4.4
-
cpe:2.3:a:kaseya:unitrends_backup:10.4.5
-
cpe:2.3:a:kaseya:unitrends_backup:10.4.6
-
cpe:2.3:a:kaseya:unitrends_backup:10.4.7
-
cpe:2.3:a:kaseya:unitrends_backup:10.4.8
-
cpe:2.3:a:kaseya:unitrends_backup:10.4.9
-
cpe:2.3:a:kaseya:unitrends_backup:10.5.0
-
cpe:2.3:a:kaseya:unitrends_backup:10.5.1
-
cpe:2.3:a:kaseya:unitrends_backup:10.5.2
-
cpe:2.3:a:kaseya:unitrends_backup:10.5.3
-
cpe:2.3:a:kaseya:unitrends_backup:10.5.4