Datto's vulnerability profile centers on a narrow but high-value product line of backup and disaster-recovery appliances—including the Alto Imaged, Alto XL, and Siris 2 series—that are widely deployed in managed service provider and small-to-medium business environments. Its disclosures skew strongly toward critical-severity outcomes and recur through weakness classes including sensitive information exposure, hard-coded credentials, and improper input validation, reflecting risks inherent to appliances that store and manage customer data at scale. Defenders should prioritize Datto appliance patching and restrict administrative access; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Datto over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-2081CRITICAL Datto ALTO and SIRIS devices allow Remote Code Execution via unauthenticated requests to PHP scripts. | Feb 20, 2018 | 9.8 | 30 | NO | NO |
CVE-2015-9254CRITICAL Datto ALTO and SIRIS devices have a default VNC password. | Feb 20, 2018 | 9.8 | 29 | NO | NO |
CVE-2017-16674HIGH Datto Windows Agent allows unauthenticated remote command execution via a modified command in conjunction with CVE-2017-16673 exploitation, aka an attack with a malformed primary w | Nov 9, 2017 | 8.0 | 26 | NO | NO |
CVE-2017-16673MEDIUM Datto Backup Agent 1.0.6.0 and earlier does not authenticate incoming connections. This allows an attacker to impersonate a Datto Backup Appliance to "pair" with the agent and issu | Nov 9, 2017 | 5.3 | 20 | NO | NO |
CVE-2015-9256MEDIUM Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information via access to device/VM restore mount points, because they do not have ACLs by default. | Feb 20, 2018 | 5.3 | 15 | NO | NO |
CVE-2015-9255MEDIUM Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information about data, software versions, configuration, and virtual machines via a request to a Web Virtua | Feb 20, 2018 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Datto.
Media articles that mention a CVE ID that affects a product developed by Datto — matched by CVE ID, not by vendor name.