9.8
CVSSv3

CVE-2018-14701

Published: 03/12/2018 Updated: 13/03/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

System command injection in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated malicious users to execute system commands via the "username" URL parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

drobo 5n2_firmware 4.0.5-13.28.96115

Exploits

Drobo 5N2 version 411 suffers from a remote command injection vulnerability ...