CVE-2025-43595

An insecure file system permissions vulnerability in MSP360 Backup 4.3.1.115 allows a low privileged user to execute commands with root privileges in the 'Online Backup' folder. Upgrade to MSP360 Backup 4.4 (released on 2025-04-22).
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:msp360:backup:4.3.1.115:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

23 Sep 2025, 15:50

Type Values Removed Values Added
References () https://help.msp360.com/cloudberry-backup-mac-linux/whats-new - () https://help.msp360.com/cloudberry-backup-mac-linux/whats-new - Release Notes
References () https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-119-01.json - () https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-119-01.json - Third Party Advisory
References () https://www.cve.org/CVERecord?id=CVE-2025-43595 - () https://www.cve.org/CVERecord?id=CVE-2025-43595 - Third Party Advisory
First Time Msp360 backup
Linux
Linux linux Kernel
Msp360
CPE cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:msp360:backup:4.3.1.115:*:*:*:*:*:*:*

22 May 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-01 22:15

Updated : 2025-09-23 15:50


NVD link : CVE-2025-43595

Mitre link : CVE-2025-43595

CVE.ORG link : CVE-2025-43595


JSON object : View

Products Affected

msp360

  • backup

linux

  • linux_kernel
CWE
CWE-276

Incorrect Default Permissions