Back to Database
Status published
Critical
CVE-2018-14699
System command injection in the /DroboAccess/enable_user endpoint in Drobo 5N2...
Vulnerability Description
System command injection in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the "username" URL parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-14699
Credits & Attribution
No credits recorded in the NVD database.
References
More from drobo
View All →CVE-2018-14709
Incorrect access control in the Dashboard API on Drobo 5N2...
Critical
9.8
CVE-2018-14708
An insecure transport protocol used by Drobo Dashboard API on...
Critical
9.8
CVE-2018-14707
Directory traversal in the Drobo Pix web application on Drobo...
High
7.5
CVE-2018-14706
System command injection in the /DroboPix/api/drobopix/demo endpoint on Drobo 5N2...
Critical
9.8
CVE-2018-14705
Lack of Authentication/Authorization on Administrative Web Pages
Critical
9.8
Affected Vendor
drobo
View all reports →Affected Software
5n2 firmware
Vulnerable Versions:
4.0.5-13.28.96115
Timeline
Official Publish:
December 3rd, 2018
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.