VYPR
Vendor

Druva

Products
5
CVEs
8
Across products
11
Status
Private

Products

5

Recent CVEs

8
  • CVE-2020-5752HigMay 21, 2020
    risk 0.54cvss 7.8epss 0.09

    Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges.

  • CVE-2019-3999HigFeb 25, 2020
    risk 0.54cvss 7.8epss 0.09

    Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges.

  • CVE-2021-36668HigJul 12, 2022
    risk 0.51cvss 7.8epss 0.01

    URL injection in Driva inSync 6.9.0 for MacOS, allows attackers to force a visit to an arbitrary url via the port parameter to the Electron App.

  • CVE-2021-36667HigJul 12, 2022
    risk 0.51cvss 7.8epss 0.02

    Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitrary commands via crafted payload to the local HTTP server due to un-sanitized call to the python os.system library.

  • CVE-2021-36666HigJul 12, 2022
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Druva 6.9.0 for MacOS, allows attackers to gain escalated local privileges via the inSyncDecommission.

  • CVE-2021-36665HigJul 12, 2022
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local privileges via the inSyncUpgradeDaemon.

  • CVE-2019-4001HigMar 24, 2020
    risk 0.51cvss 7.8epss 0.01

    Improper input validation in Druva inSync Client 6.5.0 allows a local, authenticated attacker to execute arbitrary NodeJS code.

  • CVE-2019-4000HigFeb 25, 2020
    risk 0.51cvss 7.8epss 0.01

    Improper neutralization of directives in dynamically evaluated code in Druva inSync Mac OS Client 6.5.0 allows a local, authenticated attacker to execute arbitrary Python expressions with root privileges.