Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Code42

First CVE: Jun 27, 2017Active for: 9 yearsTotal CVEs: 10
42.6
VTI Score
High

Code42 develops backup and endpoint data-protection software deployed across enterprise environments to safeguard and monitor endpoint systems, where its vulnerability profile skews toward serious outcomes with a meaningful share reaching critical severity. The recurring exposure spans its flagship products including Code42, Code42 for Enterprise, and CrashPlan offerings and centers on dangerous code-injection and deserialization weaknesses alongside improper privilege and path-handling issues, reflecting the deep system integration and privileged operations required of endpoint-protection software. Current severity, exploitation activity, and CVE counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Code42 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 27, 2017
9 years ago
Most Recent CVE
Jan 20, 2022
1,646 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-9830CRITICAL
Remote Code Execution is possible in Code42 CrashPlan 5.4.x via the org.apache.commons.ssl.rmi.DateRMI Java class, because (upon instantiation) it creates an RMI server that listen
Jun 27, 20179.833NONO
CVE-2019-15131CRITICAL
In Code42 Enterprise 6.7.5 and earlier, 6.8.4 through 6.8.8, and 7.0.0 a vulnerability has been identified that may allow arbitrary files to be uploaded to Code42 servers and execu
Sep 17, 20199.830NONO
CVE-2021-43269HIGH
In Code42 app before 8.8.0, eval injection allows an attacker to change a device’s proxy configuration to use a malicious proxy auto-config (PAC) file, leading to arbitrary code ex
Jan 20, 20228.827NONO
CVE-2019-11553HIGH
In Code42 for Enterprise through 6.8.4, an administrator without web restore permission but with the ability to manage users in an organization can impersonate a user with web rest
Jul 19, 20198.826NONO
CVE-2020-12736HIGH
Code42 environments with on-premises server versions 7.0.4 and earlier allow for possible remote code execution. When an administrator creates a local (non-SSO) user via a Code42-g
Jul 7, 20207.224NONO
CVE-2019-16861HIGH
Code42 server through 7.0.2 for Windows has an Untrusted Search Path. In certain situations, a non-administrative attacker on the local server could create or modify a dynamic-link
Nov 19, 20197.324NONO
CVE-2019-16860HIGH
Code42 app through version 7.0.2 for Windows has an Untrusted Search Path. In certain situations, a non-administrative attacker on the local machine could create or modify a dynami
Nov 19, 20197.324NONO
CVE-2018-20131HIGH
The Code42 app before 6.8.4, as used in Code42 for Enterprise, on Linux installs with overly permissive permissions on the /usr/local/crashplan/log directory. This allows a user to
Jan 3, 20197.824NONO
CVE-2019-11552HIGH
Code42 Enterprise and Crashplan for Small Business Client version 6.7 before 6.7.5, 6.8 before 6.8.8, and 6.9 before 6.9.4 allows eval injection. A proxy auto-configuration file, c
Jul 19, 20197.021NONO
CVE-2019-11551MEDIUM
In Code42 Enterprise and Crashplan for Small Business through Client version 6.9.1, an attacker can craft a restore request to restore a file through the Code42 app to a location t
Aug 21, 20195.517NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
10%
70%
20%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local5 (50.0%)
Network5 (50.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (90.0%)
High1 (10.0%)
Unknown0 (0.0%)
User Interaction
None8 (80.0%)
Unknown0 (0.0%)
Required2 (20.0%)
Privileges Required
Low7 (70.0%)
High1 (10.0%)
None2 (20.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Code42.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Code42 — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Code42's Products

View all 1 CNAs →

Top CWEs