CVE-2018-14705
Last modified
CVE-2018-14705 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. In Drobo 5N2 4.0.5, all optional applications lack any form of authentication/authorization validation. As a result, any user capable of accessing the device over the network may interact with and control these applications. EPSS estimates a 1.85% chance of exploitation in the next 30 days.
Description
In Drobo 5N2 4.0.5, all optional applications lack any form of authentication/authorization validation. As a result, any user capable of accessing the device over the network may interact with and control these applications. This not only poses a severe risk to the availability of these applications, but also poses severe risks to the confidentiality and integrity of data stored within the applications and the device itself.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Drobo | 5n2 Firmware | 4.0.5 |
References
- https://www.ise.io/casestudies/sohopelessly-broken-2-0/Third Party Advisory
- https://www.ise.io/casestudies/sohopelessly-broken-2-0/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-14705?
How severe is CVE-2018-14705?
How do I fix CVE-2018-14705?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-1470IBM Sterling File Gateway 2.2.0 through 2.2.6 could allow a …4.3
- CVE-2018-14700Incorrect access control in the /mysql/api/logfile.php endpo…
- CVE-2018-14701System command injection in the /DroboAccess/delete_user end…
- CVE-2018-14702Incorrect access control in the /drobopix/api/drobo.php endp…
- CVE-2018-14703Incorrect access control in the /mysql/api/droboapp/data end…
- CVE-2018-14704Cross-site scripting in the MySQL API error page in Drobo 5N…
- CVE-2018-14706System command injection in the /DroboPix/api/drobopix/demo …
- CVE-2018-14707Directory traversal in the Drobo Pix web application on Drob…
- CVE-2018-14708An insecure transport protocol used by Drobo Dashboard API o…
- CVE-2018-14709Incorrect access control in the Dashboard API on Drobo 5N2 N…
- CVE-2018-1471Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2018-14710Cross-site scripting in appGet.cgi on ASUS RT-AC3200 version…
Are you affected by CVE-2018-14705?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
