Known Vulnerabilities for products from Datto
Listed below are 6 of the newest known vulnerabilities associated with the vendor "Datto".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2017-16674 json | Datto Windows Agent allows unauthenticated remote command execution via a modified command in conjunction with CVE-2017-16673... | Not Provided | 2017-11-09 | 2025-04-20 |
| CVE-2017-16673 json | Datto Backup Agent 1.0.6.0 and earlier does not authenticate incoming connections. This allows an attacker to impersonate a D... | Not Provided | 2017-11-09 | 2025-04-20 |
| CVE-2015-9256 json | Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information via access to device/VM restore mount poi... | 5.3 - MEDIUM | 2018-02-20 | 2018-03-19 |
| CVE-2015-9255 json | Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information about data, software versions, configurat... | 5.3 - MEDIUM | 2018-02-20 | 2018-03-19 |
| CVE-2015-9254 json | Datto ALTO and SIRIS devices have a default VNC password. | 9.8 - CRITICAL | 2018-02-20 | 2018-03-19 |
| CVE-2015-2081 json | Datto ALTO and SIRIS devices allow Remote Code Execution via unauthenticated requests to PHP scripts. | 9.8 - CRITICAL | 2018-02-20 | 2018-03-19 |
Known software with vulnerabilities from Datto
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Datto | Backup Agent | 1.0.6.0 |
| Application | Datto | Windows Agent | 1.0.5.0 |