Data Protection Advisor

Vendor:

First CVE: Aug 1, 2011 · Active for 14 years

9
Total CVEs
More Total CVEs than 86% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 34% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Data Protection Advisor over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 1, 2011
14 years ago
Most Recent CVE
Mar 16, 2018
3,054 days ago

CVE Severity & Scoring

Data Protection Advisor9 CVEs
All CVEs352,719 CVEs
LowMediumHighCritical
Attack Vector
Local1 (11.1%)
Network4 (44.4%)
Unknown4 (44.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (55.6%)
High0 (0.0%)
Unknown4 (44.4%)
User Interaction
None5 (55.6%)
Unknown4 (44.4%)
Required0 (0.0%)
Privileges Required
Low3 (33.3%)
High1 (11.1%)
None1 (11.1%)
Unknown4 (44.4%)

Top CVEs

Signals from CVEs in this product scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The DPA_Utilities.cProcessAuthenticationData function in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote attackers to cause a denial of service (NULL pointer de
Apr 20, 20127.837NOYES
EMC Data Protection Advisor 6.3.x before patch 67 and 6.4.x before patch 130 contains undocumented accounts with hard-coded passwords and various privileges. Affected accounts are:
Mar 16, 20189.830NONO
EMC Data Protection Advisor prior to 6.4 contains multiple blind SQL injection vulnerabilities. A remote authenticated attacker may potentially exploit these vulnerabilities to gai
Jul 9, 20178.829NONO
Integer overflow in the DPA_Utilities library in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote attackers to cause a denial of service (infinite loop) via a ne
Apr 20, 20125.027NOYES
Dell EMC Data Protection Advisor versions prior to 6.3 Patch 159 and Dell EMC Data Protection Advisor versions prior to 6.4 Patch 110 contain a hardcoded database account with admi
Mar 12, 20187.824NONO
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of EMC Data Protection Advisor 6.3.0. Authentication is required to exploit this vu
Oct 19, 20178.824NONO
EMC Data Protection Advisor prior to 6.4 contains a path traversal vulnerability. A remote authenticated high privileged user may potentially exploit this vulnerability to access u
Jul 9, 20174.920NONO
Directory traversal vulnerability in the Web UI in EMC Data Protection Advisor (DPA) 5.6 through SP1, 5.7 through SP1, and 5.8 through SP4 allows remote attackers to read arbitrary
Dec 26, 20125.018NONO
EMC Data Protection Advisor before 5.8.1 places cleartext account credentials in the DPA configuration file in unspecified circumstances, which might allow local users to obtain se
Aug 1, 20112.113NONO

Exploit Exposure

Signals from CVEs in this product scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
22.2% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (9 CVEs).

Media Mentions

Signals from CVEs in this product scope (9 CVEs).

Top CNAs Publishing CVEs For Data Protection Advisor

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.4.028.81.3%00
6.3.038.83.1%00
5.845.33.7%02
5.7.112.10.3%00
5.745.03.5%02
5.6.112.10.3%00
5.645.44.0%02
5.526.45.9%02
5.012.10.3%00