Known Vulnerabilities for products from Drobo

Listed below are 15 of the newest known vulnerabilities associated with the vendor "Drobo".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2018-14709 json Incorrect access control in the Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to bypass authentic... 9.8 - CRITICAL 2018-12-03 2020-03-13
CVE-2018-14708 json An insecure transport protocol used by Drobo Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to int... 9.8 - CRITICAL 2018-12-03 2019-02-05
CVE-2018-14707 json Directory traversal in the Drobo Pix web application on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attack... 7.5 - HIGH 2018-12-03 2018-12-20
CVE-2018-14706 json System command injection in the /DroboPix/api/drobopix/demo endpoint on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauth... 9.8 - CRITICAL 2018-12-03 2019-10-03
CVE-2018-14705 json In Drobo 5N2 4.0.5, all optional applications lack any form of authentication/authorization validation. As a result, any user... 9.8 - CRITICAL 2020-02-24 2020-03-02
CVE-2018-14704 json Cross-site scripting in the MySQL API error page in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaS... 6.1 - MEDIUM 2018-12-03 2018-12-20
CVE-2018-14703 json Incorrect access control in the /mysql/api/droboapp/data endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthent... 9.8 - CRITICAL 2018-12-03 2019-10-03
CVE-2018-14702 json Incorrect access control in the /drobopix/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenti... 7.5 - HIGH 2018-12-03 2018-12-20
CVE-2018-14701 json System command injection in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthent... 9.8 - CRITICAL 2018-12-03 2020-03-13
CVE-2018-14700 json Incorrect access control in the /mysql/api/logfile.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthentic... 7.5 - HIGH 2018-12-03 2018-12-20
CVE-2018-14699 json System command injection in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthent... 9.8 - CRITICAL 2018-12-03 2019-10-03
CVE-2018-14698 json Cross-site scripting in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to ... 6.1 - MEDIUM 2018-12-03 2018-12-20
CVE-2018-14697 json Cross-site scripting in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to ... 6.1 - MEDIUM 2018-12-03 2018-12-20
CVE-2018-14696 json Incorrect access control in the /mysql/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticat... 7.5 - HIGH 2018-12-03 2018-12-20
CVE-2018-14695 json Incorrect access control in the /mysql/api/diags.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticat... 7.5 - HIGH 2018-12-03 2018-12-20

Known software with vulnerabilities from Drobo

Type Vendor Product Version
Operating
System
Drobo5n2 Firmware4.0.5

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report