Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Datto/
  3. Datto

Datto

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 6 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Backup, RMM, and PSA platform suite for MSPs and IT teams.

by Datto · datto.com · source ↗

Known CVEs (6)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2015-9256 ↗MEDIUM 5.32018

    Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information via access to device/VM restore mount points, because they do not have ACLs by default.

  • CVE-2015-9255 ↗MEDIUM 5.32018

    Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information about data, software versions, configuration, and virtual machines via a request to a Web Virtual Directory.

  • CVE-2015-9254 ↗CRITICAL 9.82018

    Datto ALTO and SIRIS devices have a default VNC password.

  • CVE-2015-2081 ↗CRITICAL 9.82018

    Datto ALTO and SIRIS devices allow Remote Code Execution via unauthenticated requests to PHP scripts.

  • CVE-2017-16674 ↗HIGH 8.02017

    Datto Windows Agent allows unauthenticated remote command execution via a modified command in conjunction with CVE-2017-16673 exploitation, aka an attack with a malformed primary whitelisted command a…

  • CVE-2017-16673 ↗MEDIUM 5.32017

    Datto Backup Agent 1.0.6.0 and earlier does not authenticate incoming connections. This allows an attacker to impersonate a Datto Backup Appliance to "pair" with the agent and issue requests to this a…

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Backup as a Service products

see all →
  • Acsense IAM Resilience Platform · Acsense
  • Ahsay Backup Amazon S3 · Ahsay Systems Corporation
  • Ahsay Backup Microsoft Azure · Ahsay Systems Corporation
  • Ahsay Google Workspace Backup · Ahsay Systems Corporation
  • Arcserve Cloud Cyber Resilient Storage · Arcserve
  • Arcserve Cyber Resilient Storage · Arcserve
  • Arpio · Arpio
  • AvePoint Products · AvePoint