ZeroHour

CVE-2017-7279

CVSS 3.0
9.8 critical
EPSS
4%p91
Published
()
Modified
Description

An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" cookie issued at login.

Vendors
unitrends
Products
enterprise backup
Weakness
CWE-565
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.