« Back to list

Datto

Datto Siris 3 Firmware: vulnerabilities and CVEs

Datto Siris 3 Firmware has 4 published vulnerabilities, 0 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.

CVEs4
Last 12 months0
Critical2
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2015-9256Medium (5.3)1.0%—Feb 20, 2018
Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information via access to device/VM restore mount points, because they do not have ACLs by default.
CVE-2015-9255Medium (5.3)1.0%—Feb 20, 2018
Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information about data, software versions, configuration, and virtual machines via a request to a Web Virtual Directory.
CVE-2015-9254Critical (9.8)1.1%—Feb 20, 2018
Datto ALTO and SIRIS devices have a default VNC password.
CVE-2015-2081Critical (9.8)2.8%—Feb 20, 2018
Datto ALTO and SIRIS devices allow Remote Code Execution via unauthenticated requests to PHP scripts.

Other products by Datto