CVE-2018-14705 Information
Feb 14, 2021
cve
Description
In Drobo 5N2 4.0.5 all optional applications lack any form of authentication/authorization validation. As a result any user capable of accessing the device over the network may interact with and control these applications. This not only poses a severe risk to the availability of these applications but also poses severe risks to the confidentiality and integrity of data stored within the applications and the device itself.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://blog.securityevaluators.com/call-me-a-doctor-new-vulnerabilities-in-drobo5n2-4f1d885df7fc https://www.ise.io/casestudies/sohopelessly-broken-2-0/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: