CVE Tools

Drobo

14 CVEs tracked since 2018. Since Dec 2018, none of them reached CISA KEV.

Drobo CVEs per month

Dec 2018 to Dec 2018. Point at a month, or focus the strip and use the arrow keys.
Drobo CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2018-12140

Products

The products that kept showing up in Drobo's monthly top three, with their CVEs summed over those months.

  1. 5n2 Firmware141 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Drobo.

  1. CVE-2018-14705Lack of Authentication/Authorization on Administrative Web Pages9.8
  2. CVE-2018-14696Incorrect access control in the /mysql/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve sensitive system information.7.5
  3. CVE-2018-14703Incorrect access control in the /mysql/api/droboapp/data endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve the MySQL database root password.9.8
  4. CVE-2018-14701System command injection in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the "username" URL param...9.8
  5. CVE-2018-14709Incorrect access control in the Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to bypass authentication due to insecure token generation.9.8
  6. CVE-2018-14702Incorrect access control in the /drobopix/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve sensitive system information.7.5
  7. CVE-2018-14706System command injection in the /DroboPix/api/drobopix/demo endpoint on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the payload in a POST...9.8
  8. CVE-2018-14698Cross-site scripting in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via the "username" URL parameter.6.1
  9. CVE-2018-14708An insecure transport protocol used by Drobo Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to intercept network traffic.9.8
  10. CVE-2018-14707Directory traversal in the Drobo Pix web application on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to upload files to arbitrary locations.7.5
  11. CVE-2018-14700Incorrect access control in the /mysql/api/logfile.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve MySQL log files via the "name" URL parameter.7.5
  12. CVE-2018-14704Cross-site scripting in the MySQL API error page in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via a malformed URL path.6.1
  13. CVE-2018-14699System command injection in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the "username" URL param...9.8
  14. CVE-2018-14695Incorrect access control in the /mysql/api/diags.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve diagnostic information via the "name" URL param...7.5
  15. CVE-2018-14697Cross-site scripting in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via the username URL parameter.6.1

The record

Peak rank
#24 in Dec 2018
Busiest month shown
Dec 2018, 14 CVEs
Months with a KEV entry
0 since Dec 2018
Monthly snapshots
1 since 2018
Drobo's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store