drobo kayıtları
drobo üreticisine ait 15 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-287 Improper Authentication3
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-532 Insertion of Sensitive Information into Log File1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
15 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
48Planlayın | CVE-2018-14699Kavram kanıtı | System command injection in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackerdrobo · 5n2 firmware · CWE-78 | Kritik9,8 | — | %29,4 | 3 Ara 2018 |
45Planlayın | CVE-2018-14701İstismar yok | System command injection in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackerdrobo · 5n2 firmware · CWE-78 | Kritik9,8 | — | %20,0 | 3 Ara 2018 |
44Planlayın | CVE-2018-14706İstismar yok | System command injection in the /DroboPix/api/drobopix/demo endpoint on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attacdrobo · 5n2 firmware · CWE-78 | Kritik9,8 | — | %17,1 | 3 Ara 2018 |
40Planlayın | CVE-2018-14709İstismar yok | Incorrect access control in the Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to bypass authentication due to indrobo · 5n2 firmware · CWE-287 | Kritik9,8 | — | %1,9 | 3 Ara 2018 |
40Planlayın | CVE-2018-14705İstismar yok | Lack of Authentication/Authorization on Administrative Web Pagesdrobo · 5n2 firmware · CWE-287 | Kritik9,8 | — | %1,9 | 24 Şub 2020 |
39İzleyin | CVE-2018-14703İstismar yok | Incorrect access control in the /mysql/api/droboapp/data endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackerdrobo · 5n2 firmware · CWE-732 | Kritik9,8 | — | %1,3 | 3 Ara 2018 |
39İzleyin | CVE-2018-14708İstismar yok | An insecure transport protocol used by Drobo Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to intercept network drobo · 5n2 firmware · CWE-287 | Kritik9,8 | — | %1,3 | 3 Ara 2018 |
38İzleyin | CVE-2018-14707İstismar yok | Directory traversal in the Drobo Pix web application on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to upload fdrobo · 5n2 firmware · CWE-22 | Yüksek7,5 | — | %27,8 | 3 Ara 2018 |
30İzleyin | CVE-2018-14702İstismar yok | Incorrect access control in the /drobopix/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackersdrobo · 5n2 firmware · CWE-200 | Yüksek7,5 | — | %1,3 | 3 Ara 2018 |
30İzleyin | CVE-2018-14696İstismar yok | Incorrect access control in the /mysql/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers todrobo · 5n2 firmware · CWE-200 | Yüksek7,5 | — | %1,3 | 3 Ara 2018 |
30İzleyin | CVE-2018-14700İstismar yok | Incorrect access control in the /mysql/api/logfile.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers drobo · 5n2 firmware · CWE-532 | Yüksek7,5 | — | %1,3 | 3 Ara 2018 |
30İzleyin | CVE-2018-14695İstismar yok | Incorrect access control in the /mysql/api/diags.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers todrobo · 5n2 firmware · CWE-200 | Yüksek7,5 | — | %1,3 | 3 Ara 2018 |
24İzleyin | CVE-2018-14704İstismar yok | Cross-site scripting in the MySQL API error page in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via a maldrobo · 5n2 firmware · CWE-79 | Orta6,1 | — | %0,7 | 3 Ara 2018 |
24İzleyin | CVE-2018-14698İstismar yok | Cross-site scripting in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScrdrobo · 5n2 firmware · CWE-79 | Orta6,1 | — | %0,7 | 3 Ara 2018 |
24İzleyin | CVE-2018-14697İstismar yok | Cross-site scripting in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScrdrobo · 5n2 firmware · CWE-79 | Orta6,1 | — | %0,7 | 3 Ara 2018 |
- CVE-2018-1469948Planlayın
System command injection in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attacker
KritikCVSS 9,8Kavram kanıtıEPSS %29drobo · 5n2 firmware3 Ara 2018
- CVE-2018-1470145Planlayın
System command injection in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attacker
KritikCVSS 9,8İstismar yokEPSS %20drobo · 5n2 firmware3 Ara 2018
- CVE-2018-1470644Planlayın
System command injection in the /DroboPix/api/drobopix/demo endpoint on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attac
KritikCVSS 9,8İstismar yokEPSS %17drobo · 5n2 firmware3 Ara 2018
- CVE-2018-1470940Planlayın
Incorrect access control in the Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to bypass authentication due to in
KritikCVSS 9,8İstismar yokEPSS %2drobo · 5n2 firmware3 Ara 2018
- CVE-2018-1470540Planlayın
Lack of Authentication/Authorization on Administrative Web Pages
KritikCVSS 9,8İstismar yokEPSS %2drobo · 5n2 firmware24 Şub 2020
- CVE-2018-1470339İzleyin
Incorrect access control in the /mysql/api/droboapp/data endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attacker
KritikCVSS 9,8İstismar yokEPSS %1drobo · 5n2 firmware3 Ara 2018
- CVE-2018-1470839İzleyin
An insecure transport protocol used by Drobo Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to intercept network
KritikCVSS 9,8İstismar yokEPSS %1drobo · 5n2 firmware3 Ara 2018
- CVE-2018-1470738İzleyin
Directory traversal in the Drobo Pix web application on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to upload f
YüksekCVSS 7,5İstismar yokEPSS %28drobo · 5n2 firmware3 Ara 2018
- CVE-2018-1470230İzleyin
Incorrect access control in the /drobopix/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers
YüksekCVSS 7,5İstismar yokEPSS %1drobo · 5n2 firmware3 Ara 2018
- CVE-2018-1469630İzleyin
Incorrect access control in the /mysql/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to
YüksekCVSS 7,5İstismar yokEPSS %1drobo · 5n2 firmware3 Ara 2018
- CVE-2018-1470030İzleyin
Incorrect access control in the /mysql/api/logfile.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers
YüksekCVSS 7,5İstismar yokEPSS %1drobo · 5n2 firmware3 Ara 2018
- CVE-2018-1469530İzleyin
Incorrect access control in the /mysql/api/diags.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to
YüksekCVSS 7,5İstismar yokEPSS %1drobo · 5n2 firmware3 Ara 2018
- CVE-2018-1470424İzleyin
Cross-site scripting in the MySQL API error page in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via a mal
OrtaCVSS 6,1İstismar yokEPSS %1drobo · 5n2 firmware3 Ara 2018
- CVE-2018-1469824İzleyin
Cross-site scripting in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScr
OrtaCVSS 6,1İstismar yokEPSS %1drobo · 5n2 firmware3 Ara 2018
- CVE-2018-1469724İzleyin
Cross-site scripting in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScr
OrtaCVSS 6,1İstismar yokEPSS %1drobo · 5n2 firmware3 Ara 2018