Drobo
Drobo 5N2 Firmware: vulnerabilidades y CVE
Drobo 5N2 Firmware tiene 15 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 7 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses0
Críticas7
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2018-14705 | Crítica (9.8) | 1.9% | — | 24 feb 2020 | In Drobo 5N2 4.0.5, all optional applications lack any form of authentication/authorization validation. As a result, any user capable of accessing the device over the network may interact with and control these… |
| CVE-2018-14709 | Crítica (9.8) | 1.9% | — | 3 dic 2018 | Incorrect access control in the Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to bypass authentication due to insecure token generation. |
| CVE-2018-14708 | Crítica (9.8) | 1.3% | — | 3 dic 2018 | An insecure transport protocol used by Drobo Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to intercept network traffic. |
| CVE-2018-14707 | Alta (7.5) | 28% | — | 3 dic 2018 | Directory traversal in the Drobo Pix web application on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to upload files to arbitrary locations. |
| CVE-2018-14706 | Crítica (9.8) | 17% | — | 3 dic 2018 | System command injection in the /DroboPix/api/drobopix/demo endpoint on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the payload in a POST request. |
| CVE-2018-14704 | Media (6.1) | 0.71% | — | 3 dic 2018 | Cross-site scripting in the MySQL API error page in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via a malformed URL path. |
| CVE-2018-14703 | Crítica (9.8) | 1.3% | — | 3 dic 2018 | Incorrect access control in the /mysql/api/droboapp/data endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve the MySQL database root password. |
| CVE-2018-14702 | Alta (7.5) | 1.3% | — | 3 dic 2018 | Incorrect access control in the /drobopix/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve sensitive system information. |
| CVE-2018-14701 | Crítica (9.8) | 20% | — | 3 dic 2018 | System command injection in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the "username" URL parameter. |
| CVE-2018-14700 | Alta (7.5) | 1.3% | — | 3 dic 2018 | Incorrect access control in the /mysql/api/logfile.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve MySQL log files via the "name" URL parameter. |
| CVE-2018-14699 | Crítica (9.8) | 29% | — | 3 dic 2018 | System command injection in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the "username" URL parameter. |
| CVE-2018-14698 | Media (6.1) | 0.71% | — | 3 dic 2018 | Cross-site scripting in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via the "username" URL parameter. |
| CVE-2018-14697 | Media (6.1) | 0.71% | — | 3 dic 2018 | Cross-site scripting in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via the username URL parameter. |
| CVE-2018-14696 | Alta (7.5) | 1.3% | — | 3 dic 2018 | Incorrect access control in the /mysql/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve sensitive system information. |
| CVE-2018-14695 | Alta (7.5) | 1.3% | — | 3 dic 2018 | Incorrect access control in the /mysql/api/diags.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve diagnostic information via the "name" URL parameter. |