Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-16673

Опубликовано: 09 нояб. 2017
Источник: nvd
CVSS3: 5.3
CVSS2: 2.9
EPSS Низкий

Описание

Datto Backup Agent 1.0.6.0 and earlier does not authenticate incoming connections. This allows an attacker to impersonate a Datto Backup Appliance to "pair" with the agent and issue requests to this agent, if the attacker can reach the agent on TCP port 25566 or 25568, and send unspecified "specific information" by which the agent identifies a network device that is "appearing to be a valid Datto."

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:datto:backup_agent:*:*:*:*:*:*:*:*
Версия до 1.0.6.0 (включая)

EPSS

Процентиль: 25%
0.00085
Низкий

5.3 Medium

CVSS3

2.9 Low

CVSS2

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.3
github
больше 3 лет назад

Datto Backup Agent 1.0.6.0 and earlier does not authenticate incoming connections. This allows an attacker to impersonate a Datto Backup Appliance to "pair" with the agent and issue requests to this agent, if the attacker can reach the agent on TCP port 25566 or 25568, and send unspecified "specific information" by which the agent identifies a network device that is "appearing to be a valid Datto."

EPSS

Процентиль: 25%
0.00085
Низкий

5.3 Medium

CVSS3

2.9 Low

CVSS2

Дефекты

CWE-200