Datto
datto
6 CVEs • 18 products
Products (18)
Click to collapseToggle
Products (18)
Click to collapse
CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Datto 8Alto 2 Firmware Alto 3 FirmwareAlto Imaged Firmware+5 moreNov 21, 2024 Feb 20, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information via access to device/VM restore mount points, because they do not have ACLs by default. |
1Datto 8Alto 2 Firmware Alto 3 FirmwareAlto Imaged Firmware+5 moreNov 21, 2024 Feb 20, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information about data, software versions, configuration, and virtual machines via a request to a Web Virtual Directory. |
1Datto 8Alto 2 Firmware Alto 3 FirmwareAlto Imaged Firmware+5 moreNov 21, 2024 Feb 20, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Datto ALTO and SIRIS devices have a default VNC password. |
1Datto 8Alto 2 Firmware Alto 3 FirmwareAlto Imaged Firmware+5 moreNov 21, 2024 Feb 20, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Datto ALTO and SIRIS devices allow Remote Code Execution via unauthenticated requests to PHP scripts. |
Datto Windows Agent allows unauthenticated remote command execution via a modified command in conjunction with CVE-2017-16673 exploitation, aka an attack with a malformed primary whitelisted command and a secondary non-w...Show more |
Datto Backup Agent 1.0.6.0 and earlier does not authenticate incoming connections. This allows an attacker to impersonate a Datto Backup Appliance to "pair" with the agent and issue requests to this agent, if the attacke...Show more |