Search: "datto"

6 CVEs found

CVE-2017-16673
5.3 MEDIUM

Datto Backup Agent 1.0.6.0 and earlier does not authenticate incoming connections. This allows an attacker to impersonate a Datto Backup Appliance to "pair" with the agent and issue requests to this a...

Published: 2017-11-09
Products: 1
Vendors:
datto

Datto Windows Agent allows unauthenticated remote command execution via a modified command in conjunction with CVE-2017-16673 exploitation, aka an attack with a malformed primary whitelisted command a...

Published: 2017-11-09
Products: 1
Vendors:
datto
CVE-2015-2081
9.8 CRITICAL

Datto ALTO and SIRIS devices allow Remote Code Execution via unauthenticated requests to PHP scripts.

Published: 2018-02-20
Products: 16
Vendors:
datto
CVE-2015-9254
9.8 CRITICAL

Datto ALTO and SIRIS devices have a default VNC password.

Published: 2018-02-20
Products: 16
Vendors:
datto
CVE-2015-9255
5.3 MEDIUM

Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information about data, software versions, configuration, and virtual machines via a request to a Web Virtual Directory.

Published: 2018-02-20
Products: 16
Vendors:
datto
CVE-2015-9256
5.3 MEDIUM

Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information via access to device/VM restore mount points, because they do not have ACLs by default.

Published: 2018-02-20
Products: 16
Vendors:
datto