Three Zero-Day Bugs Plague Kaseya Unitrends Backup Servers
#1
Information 
Quote:There are three new, unpatched zero-day vulnerabilities in Kaseya Unitrends that include remote code execution (RCE) and authenticated privilege escalation on the client-side.
 
The Dutch Institute for Vulnerability Disclosure (DIVD) on Monday issued a public advisory warning that the service and clients should be kept off the internet until there’s a patch.
 
Kaseya Unitrends is a cloud-based enterprise backup and disaster recovery technology that’s delivered as either disaster recovery-as-a-service (DRaaS) or as an add-on for the Kaseya Virtual System/Server Administrator (VSA) remote management platform. The flaws are in versions earlier than 10.5.2.
Quote:Do not expose this service or the clients (running default on ports 80, 443, 1743, 1745) directly to the internet until Kaseya has patched these vulnerabilities. —DIVD advisory

Read more: Three Zero-Day Bugs Plague Kaseya Unitrends Backup Servers | Threatpost
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
AirVPN
AirVPN UK Infrastr...jasonX — 20:29
AIDA64 by FinalWire
AIDA64 v8.25 RELEASE...jasonX — 19:46
Google Updates Wear OS to Deliver Earthq...
Google is updating...harlan4096 — 12:28
HWiNFO v8.42
HWiNFO v8.42 Re...harlan4096 — 11:04
Mozilla Firefox Browser 148.0
Mozilla Firefox Br...harlan4096 — 08:24

[-]
Birthdays
Today's Birthdays
avatar (44)Baihu
Upcoming Birthdays
No upcoming birthdays.

[-]
Online Staff
There are no staff members currently online.

>