PT-2018-12679 · Drobo · Drobo 5N2 Nas+1

Published

2018-12-03

·

Updated

2019-02-05

·

CVE-2018-14708

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Drobo 5N2 NAS version 4.0.5-13.28.96115
Description The issue concerns the use of an insecure transport protocol by the Drobo Dashboard API, which allows attackers to intercept network traffic.
Recommendations For Drobo 5N2 NAS version 4.0.5-13.28.96115, consider disabling the Drobo Dashboard API until a secure transport protocol is implemented. Restrict access to the API to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-14708

Affected Products

Drobo 5N2 Nas
Drobo Dashboard Api