AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-14695

HIGH · CVSS 7.5 EPSS 1.31%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-12-03 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. Exploitation may require the attacker to be authenticated.

CVE
CVE-2018-14695
Severity
HIGH
CVSS
7.5
EPSS
1.31%

Original NVD Description

Incorrect access control in the /mysql/api/diags.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve diagnostic information via the "name" URL parameter.

Related CVEs

Other vulnerabilities affecting the same vendor(s)