CVE-2020-15851

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
24/09/2020
Last modified:
05/04/2022

Description

Lack of access control in Nakivo Backup & Replication Transporter version 9.4.0.r43656 allows remote users to access unencrypted backup repositories and the Nakivo Controller configuration via a network accessible transporter service. It is also possible to create or delete backup repositories.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nakivo:backup_\&_replication_transporter:9.4.0.r43656:*:*:*:*:*:*:*