Записи datto
6 опубликованных записей вендора datto.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-20 Improper Input Validation1
- CWE-798 Use of Hard-coded Credentials1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2015-2081Эксплойта нет | Datto ALTO and SIRIS devices allow Remote Code Execution via unauthenticated requests to PHP scripts.datto · alto 3 firmware · CWE-20 | Критическая9,8 | — | 2,8 % | 20 февр. 2018 г. |
39Наблюдать | CVE-2015-9254Эксплойта нет | Datto ALTO and SIRIS devices have a default VNC password.datto · alto 3 firmware · CWE-798 | Критическая9,8 | — | 1,1 % | 20 февр. 2018 г. |
32Наблюдать | CVE-2017-16674Эксплойта нет | Datto Windows Agent allows unauthenticated remote command execution via a modified command in conjunction with CVE-2017-16673 exploitation, datto · windows agent | Высокая8,0 | — | 0,7 % | 9 нояб. 2017 г. |
21Наблюдать | CVE-2015-9255Эксплойта нет | Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information about data, software versions, configuration, and virtuadatto · alto 3 firmware · CWE-200 | Средняя5,3 | — | 1,0 % | 20 февр. 2018 г. |
21Наблюдать | CVE-2015-9256Эксплойта нет | Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information via access to device/VM restore mount points, because thdatto · alto 3 firmware · CWE-200 | Средняя5,3 | — | 1,0 % | 20 февр. 2018 г. |
21Наблюдать | CVE-2017-16673Эксплойта нет | Datto Backup Agent 1.0.6.0 and earlier does not authenticate incoming connections.datto · backup agent · CWE-200 | Средняя5,3 | — | 0,4 % | 9 нояб. 2017 г. |
- CVE-2015-208140В плане
Datto ALTO and SIRIS devices allow Remote Code Execution via unauthenticated requests to PHP scripts.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %datto · alto 3 firmware20 февр. 2018 г.
- CVE-2015-925439Наблюдать
Datto ALTO and SIRIS devices have a default VNC password.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %datto · alto 3 firmware20 февр. 2018 г.
- CVE-2017-1667432Наблюдать
Datto Windows Agent allows unauthenticated remote command execution via a modified command in conjunction with CVE-2017-16673 exploitation,
ВысокаяCVSS 8,0Эксплойта нетEPSS 1 %datto · windows agent9 нояб. 2017 г.
- CVE-2015-925521Наблюдать
Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information about data, software versions, configuration, and virtua
СредняяCVSS 5,3Эксплойта нетEPSS 1 %datto · alto 3 firmware20 февр. 2018 г.
- CVE-2015-925621Наблюдать
Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information via access to device/VM restore mount points, because th
СредняяCVSS 5,3Эксплойта нетEPSS 1 %datto · alto 3 firmware20 февр. 2018 г.
- CVE-2017-1667321Наблюдать
Datto Backup Agent 1.0.6.0 and earlier does not authenticate incoming connections.
СредняяCVSS 5,3Эксплойта нетEPSS 0 %datto · backup agent9 нояб. 2017 г.