VYPR
Vendor

Datto

Products
12
CVEs
6
Across products
42
Status
Private

Products

12

Recent CVEs

6
  • CVE-2015-9254CriFeb 20, 2018
    risk 0.64cvss 9.8epss 0.01

    Datto ALTO and SIRIS devices have a default VNC password.

  • CVE-2015-2081CriFeb 20, 2018
    risk 0.64cvss 9.8epss 0.03

    Datto ALTO and SIRIS devices allow Remote Code Execution via unauthenticated requests to PHP scripts.

  • CVE-2017-16674HigNov 9, 2017
    risk 0.52cvss 8.0epss 0.01

    Datto Windows Agent allows unauthenticated remote command execution via a modified command in conjunction with CVE-2017-16673 exploitation, aka an attack with a malformed primary whitelisted command and a secondary non-whitelisted command. This affects Datto Windows Agent (DWA)…

  • CVE-2015-9256MedFeb 20, 2018
    risk 0.35cvss 5.3epss 0.01

    Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information via access to device/VM restore mount points, because they do not have ACLs by default.

  • CVE-2015-9255MedFeb 20, 2018
    risk 0.35cvss 5.3epss 0.01

    Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information about data, software versions, configuration, and virtual machines via a request to a Web Virtual Directory.

  • CVE-2017-16673MedNov 9, 2017
    risk 0.34cvss 5.3epss 0.00

    Datto Backup Agent 1.0.6.0 and earlier does not authenticate incoming connections. This allows an attacker to impersonate a Datto Backup Appliance to "pair" with the agent and issue requests to this agent, if the attacker can reach the agent on TCP port 25566 or 25568, and send…