Data Protection Advisor
Vendor:
First CVE: Aug 1, 2011 · Active for 14 years
9
Total CVEs
More Total CVEs than 86% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 34% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Data Protection Advisor over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 1, 2011
14 years ago
Most Recent CVE
Mar 16, 2018
3,054 days ago
CVE Severity & Scoring
Data Protection Advisor9 CVEs
11%
33%
44%
11%
All CVEs352,719 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (11.1%)
Network4 (44.4%)
Unknown4 (44.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (55.6%)
High0 (0.0%)
Unknown4 (44.4%)
User Interaction
None5 (55.6%)
Unknown4 (44.4%)
Required0 (0.0%)
Privileges Required
Low3 (33.3%)
High1 (11.1%)
None1 (11.1%)
Unknown4 (44.4%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-0406HIGH The DPA_Utilities.cProcessAuthenticationData function in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote attackers to cause a denial of service (NULL pointer de | Apr 20, 2012 | 7.8 | 37 | NO | YES |
CVE-2017-8013CRITICAL EMC Data Protection Advisor 6.3.x before patch 67 and 6.4.x before patch 130 contains undocumented accounts with hard-coded passwords and various privileges. Affected accounts are: | Mar 16, 2018 | 9.8 | 30 | NO | NO |
CVE-2017-8002HIGH EMC Data Protection Advisor prior to 6.4 contains multiple blind SQL injection vulnerabilities. A remote authenticated attacker may potentially exploit these vulnerabilities to gai | Jul 9, 2017 | 8.8 | 29 | NO | NO |
CVE-2012-0407MEDIUM Integer overflow in the DPA_Utilities library in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote attackers to cause a denial of service (infinite loop) via a ne | Apr 20, 2012 | 5.0 | 27 | NO | YES |
CVE-2018-1206HIGH Dell EMC Data Protection Advisor versions prior to 6.3 Patch 159 and Dell EMC Data Protection Advisor versions prior to 6.4 Patch 110 contain a hardcoded database account with admi | Mar 12, 2018 | 7.8 | 24 | NO | NO |
CVE-2017-10955HIGH This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of EMC Data Protection Advisor 6.3.0. Authentication is required to exploit this vu | Oct 19, 2017 | 8.8 | 24 | NO | NO |
CVE-2017-8003MEDIUM EMC Data Protection Advisor prior to 6.4 contains a path traversal vulnerability. A remote authenticated high privileged user may potentially exploit this vulnerability to access u | Jul 9, 2017 | 4.9 | 20 | NO | NO |
CVE-2012-4616MEDIUM Directory traversal vulnerability in the Web UI in EMC Data Protection Advisor (DPA) 5.6 through SP1, 5.7 through SP1, and 5.8 through SP4 allows remote attackers to read arbitrary | Dec 26, 2012 | 5.0 | 18 | NO | NO |
EMC Data Protection Advisor before 5.8.1 places cleartext account credentials in the DPA configuration file in unspecified circumstances, which might allow local users to obtain se | Aug 1, 2011 | 2.1 | 13 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
22.2% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Data Protection Advisor
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.4.0 | 2 | 8.8 | 1.3% | 0 | 0 |
| 6.3.0 | 3 | 8.8 | 3.1% | 0 | 0 |
| 5.8 | 4 | 5.3 | 3.7% | 0 | 2 |
| 5.7.1 | 1 | 2.1 | 0.3% | 0 | 0 |
| 5.7 | 4 | 5.0 | 3.5% | 0 | 2 |
| 5.6.1 | 1 | 2.1 | 0.3% | 0 | 0 |
| 5.6 | 4 | 5.4 | 4.0% | 0 | 2 |
| 5.5 | 2 | 6.4 | 5.9% | 0 | 2 |
| 5.0 | 1 | 2.1 | 0.3% | 0 | 0 |