Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Druva/
  3. Druva Enterprise Data Protection

Druva Enterprise Data Protection

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 7 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Cloud-based enterprise data backup and recovery with encryption and security

by Druva · druva.com · source ↗

Known CVEs (7)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2021-36667 ↗HIGH 7.82022

    Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitrary commands via crafted payload to the local HTTP server due to un-sanitized call to the python os.s…

  • CVE-2021-36666 ↗HIGH 7.82022

    An issue was discovered in Druva 6.9.0 for MacOS, allows attackers to gain escalated local privileges via the inSyncDecommission.

  • CVE-2021-36665 ↗HIGH 7.82022

    An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local privileges via the inSyncUpgradeDaemon.

  • CVE-2020-5752 ↗HIGH 7.82020

    Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges.

  • CVE-2019-4001 ↗HIGH 7.82020

    Improper input validation in Druva inSync Client 6.5.0 allows a local, authenticated attacker to execute arbitrary NodeJS code.

  • CVE-2019-4000 ↗HIGH 7.82020

    Improper neutralization of directives in dynamically evaluated code in Druva inSync Mac OS Client 6.5.0 allows a local, authenticated attacker to execute arbitrary Python expressions with root privile…

  • CVE-2019-3999 ↗HIGH 7.82020

    Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYST…

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Backup as a Service products

see all →
  • Acsense IAM Resilience Platform · Acsense
  • Ahsay Backup Amazon S3 · Ahsay Systems Corporation
  • Ahsay Backup Microsoft Azure · Ahsay Systems Corporation
  • Ahsay Google Workspace Backup · Ahsay Systems Corporation
  • Arcserve Cloud Cyber Resilient Storage · Arcserve
  • Arcserve Cyber Resilient Storage · Arcserve
  • Arpio · Arpio
  • AvePoint Products · AvePoint