Home/Product/drobo 5n2 firmware
Product

drobo 5n2 firmware

15 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2018-14705
all versions
In Drobo 5N2 4.0.5, all optional applications lack any form of authentication/authorization validation. As a result, any user capa
9.8CRITICAL
CVE-2018-14709
all versions
Incorrect access control in the Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to bypass authentication
9.8CRITICAL
CVE-2018-14708
all versions
An insecure transport protocol used by Drobo Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to intercep
9.8CRITICAL
CVE-2018-14707
all versions
Directory traversal in the Drobo Pix web application on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers t
7.5HIGH
CVE-2018-14706
all versions
System command injection in the /DroboPix/api/drobopix/demo endpoint on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthentic
9.8CRITICAL
CVE-2018-14704
all versions
Cross-site scripting in the MySQL API error page in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript
6.1MEDIUM
CVE-2018-14703
all versions
Incorrect access control in the /mysql/api/droboapp/data endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticate
9.8CRITICAL
CVE-2018-14702
all versions
Incorrect access control in the /drobopix/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated
7.5HIGH
CVE-2018-14701
all versions
System command injection in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticate
9.8CRITICAL
CVE-2018-14700
all versions
Incorrect access control in the /mysql/api/logfile.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated
7.5HIGH
CVE-2018-14699
all versions
System command injection in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticate
9.8CRITICAL
CVE-2018-14698
all versions
Cross-site scripting in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execu
6.1MEDIUM
CVE-2018-14697
all versions
Cross-site scripting in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execu
6.1MEDIUM
CVE-2018-14696
all versions
Incorrect access control in the /mysql/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated at
7.5HIGH
CVE-2018-14695
all versions
Incorrect access control in the /mysql/api/diags.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated at
7.5HIGH
threatengine.sh