CVE-2018-14705
Last modified
CVE-2018-14705 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. In Drobo 5N2 4.0.5, all optional applications lack any form of authentication/authorization validation. As a result, any user capable of accessing the device over the network may interact with and control these applications. EPSS estimates a 1.85% chance of exploitation in the next 30 days.
Description
In Drobo 5N2 4.0.5, all optional applications lack any form of authentication/authorization validation. As a result, any user capable of accessing the device over the network may interact with and control these applications. This not only poses a severe risk to the availability of these applications, but also poses severe risks to the confidentiality and integrity of data stored within the applications and the device itself.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Drobo | 5n2 Firmware | 4.0.5 |
References
- https://www.ise.io/casestudies/sohopelessly-broken-2-0/Third Party Advisory
- https://www.ise.io/casestudies/sohopelessly-broken-2-0/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-14705?
How severe is CVE-2018-14705?
How do I fix CVE-2018-14705?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-1470IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a …4.3
- CVE-2018-14700Incorrect access control in the /mysql/api/logfile.php endpo…
- CVE-2018-14701System command injection in the /DroboAccess/delete_user end…
- CVE-2018-14702Incorrect access control in the /drobopix/api/drobo.php endp…
- CVE-2018-14703Incorrect access control in the /mysql/api/droboapp/data end…
- CVE-2018-14704Cross-site scripting in the MySQL API error page in Drobo 5N…
- CVE-2018-14706System command injection in the /DroboPix/api/drobopix/demo …
- CVE-2018-14707Directory traversal in the Drobo Pix web application on Drob…
- CVE-2018-14708An insecure transport protocol used by Drobo Dashboard API o…
- CVE-2018-14709Incorrect access control in the Dashboard API on Drobo 5N2 N…
- CVE-2018-1471Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2018-14710Cross-site scripting in appGet.cgi on ASUS RT-AC3200 version…
Are you affected by CVE-2018-14705?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
