Skip to main content

Vendor/product archive

drobo / 5n2 CVEs

Beta · best-effort

15 CVEs tagged to drobo / 5n27 Critical, 5 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2018-14705

Published Feb 24, 2020

In Drobo 5N2 4.0.5, all optional applications lack any form of authentication/authorization validation. As a result, any user capable of accessing the device over the network may…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-14709

Published Dec 3, 2018

Incorrect access control in the Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to bypass authentication due to insecure token generation.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-14708

Published Dec 3, 2018

An insecure transport protocol used by Drobo Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to intercept network traffic.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-14707

Published Dec 3, 2018

Directory traversal in the Drobo Pix web application on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to upload files to arbitrary locations.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-14706

Published Dec 3, 2018

System command injection in the /DroboPix/api/drobopix/demo endpoint on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-14704

Published Dec 3, 2018

Cross-site scripting in the MySQL API error page in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via a malformed URL path.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-14703

Published Dec 3, 2018

Incorrect access control in the /mysql/api/droboapp/data endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve the MySQL database root p…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-14702

Published Dec 3, 2018

Incorrect access control in the /drobopix/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve sensitive system informati…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-14701

Published Dec 3, 2018

System command injection in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the "u…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-14700

Published Dec 3, 2018

Incorrect access control in the /mysql/api/logfile.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve MySQL log files via the "na…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-14699

Published Dec 3, 2018

System command injection in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the "u…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-14698

Published Dec 3, 2018

Cross-site scripting in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via the "username" URL parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-14697

Published Dec 3, 2018

Cross-site scripting in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via the username URL parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-14696

Published Dec 3, 2018

Incorrect access control in the /mysql/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve sensitive system information.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-14695

Published Dec 3, 2018

Incorrect access control in the /mysql/api/diags.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve diagnostic information via th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1