CVE Feed

    Dashboard / CVE / CVE-2017-16673

    CVE-2017-16673

    Datto Backup Agent 1.0.6.0 and earlier does not authenticate incoming connections. This allows an attacker to impersonate a Datto Backup Appliance to "pair" with the agent and issue requests to this agent, if the attacker can reach the agent on TCP port 25566 or 25568, and send unspecified "specific information" by which the agent identifies a network device that is "appearing to be a valid Datto."

    Published:Nov 9, 2017
    Last Modified:Apr 20, 2025
    EPS:Nov 9, 2017
    EPSS Score:0.00085
    CVSS Score:5.3

    Affected Products

    Vendor
    Datto
    Product
    Backup Agent

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High