cbcvebase.

Druva Insync Client vulnerabilities

6 known vulnerabilities affecting druva/insync_client.

Total CVEs
6
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
HIGH6

Vulnerabilities

Page 1 of 1
CVE-2020-5752P3HIGHCVSS 7.8PoCv6.6.32020-05-21
CVE-2020-5752 [HIGH] CWE-22 CVE-2020-5752: Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacke Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges.
nvd
CVE-2019-3999P2HIGHCVSS 7.8PoCv6.5.02020-02-25
CVE-2019-3999 [HIGH] CWE-78 CVE-2019-3999: Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5 Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges.
nvd
CVE-2021-36667P3HIGHCVSS 7.8fixed in 7.0.02022-07-12
CVE-2021-36667 [HIGH] CWE-78 CVE-2021-36667: Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitra Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitrary commands via crafted payload to the local HTTP server due to un-sanitized call to the python os.system library.
nvd
CVE-2021-36668P3HIGHCVSS 7.8fixed in 5.9.3fixed in 7.0.12022-07-12
CVE-2021-36668 [HIGH] CWE-74 CVE-2021-36668: URL injection in Driva inSync 6.9.0 for MacOS, allows attackers to force a visit to an arbitrary url URL injection in Driva inSync 6.9.0 for MacOS, allows attackers to force a visit to an arbitrary url via the port parameter to the Electron App.
nvd
CVE-2021-36665P3HIGHCVSS 7.8fixed in 7.0.02022-07-12
CVE-2021-36665 [HIGH] CWE-502 CVE-2021-36665: An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local privilege An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local privileges via the inSyncUpgradeDaemon.
nvd
CVE-2021-36666P3HIGHCVSS 7.8fixed in 7.0.02022-07-12
CVE-2021-36666 [HIGH] CWE-426 CVE-2021-36666: An issue was discovered in Druva 6.9.0 for MacOS, allows attackers to gain escalated local privilege An issue was discovered in Druva 6.9.0 for MacOS, allows attackers to gain escalated local privileges via the inSyncDecommission.
nvd