Vulnerabilities > Nakivo

DATE CVE VULNERABILITY TITLE RISK
2020-09-24 CVE-2020-15851 Missing Authentication for Critical Function vulnerability in Nakivo Backup & Replication Transporter 9.4.0.R43656
Lack of access control in Nakivo Backup & Replication Transporter version 9.4.0.r43656 allows remote users to access unencrypted backup repositories and the Nakivo Controller configuration via a network accessible transporter service.
network
low complexity
nakivo CWE-306
7.5
2020-09-24 CVE-2020-15850 Incorrect Default Permissions vulnerability in Nakivo Backup & Replication Director 9.4.0.R43656
Insecure permissions in Nakivo Backup & Replication Director version 9.4.0.r43656 on Linux allow local users to access the Nakivo Director web interface and gain root privileges.
local
low complexity
nakivo CWE-276
7.2