Unitrends response to security vulnerabilities (CVEs)

SUMMARY

This article serves as a reference for Unitrends responses to Common Vulnerabilities and Exposures (CVE).

ISSUE

When a security vulnerability CVE report is issued, how can I know if Unitrends is impacted?

CVE and NIST organizations publish security vulnerability reports as they are discovered, and the use cases where the vulnerability occurs are also described.  The Unitrends engineering organization must evaluate each of these to determine if there is any vulnerability exposed for Unitrends appliance and take corrective action if needed.

Security updates are included in normal monthly appliance updates. 

You don't need to take any manual action to get the latest security packages other than updating to the current Unitrends appliance release.  

RESOLUTION

Before contacting Unitrends Support about a possible CVE reported by a scanner, do the following:

  1. Update your hot copy targets to the latest Unitrends release.
  2. Update your appliance to the latest Unitrends release.
    An active support agreement is required to get the latest release from Unitrends.  
  3. Wait 30 minutes after the update finishes, then check your appliance for an alert indicating a reboot is required.  Only reboot if you see an alert that you need to.
  4. Scan your system with the latest updates from your security vulnerability scanner.
  5. Compare the results of your scan with this list of known false positives.
  6. Notify Unitrends support know about any CVEs your tool reports that Unitrends triggered that are not in the list of known false positives.

Unitrends provides long-term support for all software delivered on our systems for customers covered under an active Unitrends support agreement.  When Unitrends determines that functional or security issues require an update, Unitrends will supply an updated software package.  This includes providing updated OS packages, updated Unitrends software packages, or other custom software packages used by Unitrends.

 

Have more questions?

Contact us

Was this article helpful?
1 out of 1 found this helpful

Provide feedback for the Documentation team!

Browse this section