Products: 2
    Vulnerabilities: 15
    Known Exploited: 0
    7
    Critical Level Threats
    5
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2018-14705

    Lack of Authentication/Authorization on Administrative Web Pages

    Last Modified: Nov 21, 2024
    Published: Feb 24, 2020

    CVE-2018-14697

    Cross-site scripting in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via the username URL parameter.

    Last Modified: Nov 21, 2024
    Published: Dec 03, 2018

    CVE-2018-14698

    Cross-site scripting in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via the "username" URL parameter.

    Last Modified: Nov 21, 2024
    Published: Dec 03, 2018

    CVE-2018-14699

    System command injection in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the "username" URL parameter.

    Last Modified: Nov 21, 2024
    Published: Dec 03, 2018

    CVE-2018-14696

    Incorrect access control in the /mysql/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve sensitive system information.

    Last Modified: Nov 21, 2024
    Published: Dec 03, 2018
    Items Per Page