Vulnerabilities
Vulnerable Software
Druva:  >> Insync Client  Security Vulnerabilities
An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local privileges via the inSyncUpgradeDaemon.
CVSS Score
7.8
EPSS Score
0.002
Published
2022-07-12
An issue was discovered in Druva 6.9.0 for MacOS, allows attackers to gain escalated local privileges via the inSyncDecommission.
CVSS Score
7.8
EPSS Score
0.001
Published
2022-07-12
Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitrary commands via crafted payload to the local HTTP server due to un-sanitized call to the python os.system library.
CVSS Score
7.8
EPSS Score
0.011
Published
2022-07-12
URL injection in Driva inSync 6.9.0 for MacOS, allows attackers to force a visit to an arbitrary url via the port parameter to the Electron App.
CVSS Score
7.8
EPSS Score
0.002
Published
2022-07-12
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges.
CVSS Score
7.8
EPSS Score
0.167
Published
2020-05-21
Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges.
CVSS Score
7.8
EPSS Score
0.166
Published
2020-02-25


Contact Us

Shodan ® - All rights reserved