druva records
9 published records for vendor druva.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 22.2%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-276 Incorrect Default Permissions1
- CWE-426 Untrusted Search Path1
- CWE-502 Deserialization of Untrusted Data1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
34Monitor | CVE-2020-5752Weaponized | Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitrary operating system druva · insync client · CWE-22 | High7.8 | — | 8.6% | May 21, 2020 |
34Monitor | CVE-2019-3999Weaponized | Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated attacdruva · insync client · CWE-78 | High7.8 | — | 8.6% | Feb 25, 2020 |
32Monitor | CVE-2021-36667No exploit | Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitrary commands via crafted payload to the ldruva · insync client · CWE-78 | High7.8 | — | 2.7% | Jul 12, 2022 |
31Monitor | CVE-2019-4000No exploit | Improper neutralization of directives in dynamically evaluated code in Druva inSync Mac OS Client 6.5.0 allows a local, authenticated attackdruva · insync · CWE-94 | High7.8 | — | 0.7% | Feb 25, 2020 |
31Monitor | CVE-2021-36668No exploit | URL injection in Driva inSync 6.9.0 for MacOS, allows attackers to force a visit to an arbitrary url via the port parameter to the Electron druva · insync client · CWE-74 | High7.8 | — | 0.6% | Jul 12, 2022 |
31Monitor | CVE-2019-4001No exploit | Improper input validation in Druva inSync Client 6.5.0 allows a local, authenticated attacker to execute arbitrary NodeJS code.druva · insync · CWE-20 | High7.8 | — | 0.6% | Mar 24, 2020 |
31Monitor | CVE-2021-36665No exploit | An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local privileges via the inSyncUpgradeDaemon.druva · insync client · CWE-502 | High7.8 | — | 0.5% | Jul 12, 2022 |
31Monitor | CVE-2021-36666No exploit | An issue was discovered in Druva 6.9.0 for MacOS, allows attackers to gain escalated local privileges via the inSyncDecommission.druva · insync client · CWE-426 | High7.8 | — | 0.5% | Jul 12, 2022 |
31Monitor | CVE-2020-5798No exploit | inSync Client installer for macOS versions v6.8.0 and prior could allow an attacker to gain privileges of a root user from a lower privilegedruva · insync · CWE-276 | High7.8 | — | 0.3% | Dec 7, 2020 |
- CVE-2020-575234Monitor
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitrary operating system
HighCVSS 7.8WeaponizedEPSS 9%druva · insync clientMay 21, 2020
- CVE-2019-399934Monitor
Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated attac
HighCVSS 7.8WeaponizedEPSS 9%druva · insync clientFeb 25, 2020
- CVE-2021-3666732Monitor
Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitrary commands via crafted payload to the l
HighCVSS 7.8No exploitEPSS 3%druva · insync clientJul 12, 2022
- CVE-2019-400031Monitor
Improper neutralization of directives in dynamically evaluated code in Druva inSync Mac OS Client 6.5.0 allows a local, authenticated attack
HighCVSS 7.8No exploitEPSS 1%druva · insyncFeb 25, 2020
- CVE-2021-3666831Monitor
URL injection in Driva inSync 6.9.0 for MacOS, allows attackers to force a visit to an arbitrary url via the port parameter to the Electron
HighCVSS 7.8No exploitEPSS 1%druva · insync clientJul 12, 2022
- CVE-2019-400131Monitor
Improper input validation in Druva inSync Client 6.5.0 allows a local, authenticated attacker to execute arbitrary NodeJS code.
HighCVSS 7.8No exploitEPSS 1%druva · insyncMar 24, 2020
- CVE-2021-3666531Monitor
An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local privileges via the inSyncUpgradeDaemon.
HighCVSS 7.8No exploitEPSS 1%druva · insync clientJul 12, 2022
- CVE-2021-3666631Monitor
An issue was discovered in Druva 6.9.0 for MacOS, allows attackers to gain escalated local privileges via the inSyncDecommission.
HighCVSS 7.8No exploitEPSS 0%druva · insync clientJul 12, 2022
- CVE-2020-579831Monitor
inSync Client installer for macOS versions v6.8.0 and prior could allow an attacker to gain privileges of a root user from a lower privilege
HighCVSS 7.8No exploitEPSS 0%druva · insyncDec 7, 2020