Vulnerability Name: | CVE-2018-11170 (CCN-144216) | ||||||||||||
Assigned: | 2018-05-31 | ||||||||||||
Published: | 2018-05-31 | ||||||||||||
Updated: | 2019-10-03 | ||||||||||||
Summary: | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 28 of 46). | ||||||||||||
CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
8.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 6.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-78 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2018-11170 Source: MISC Type: Third Party Advisory, VDB Entry http://packetstormsecurity.com/files/148003/Quest-DR-Series-Disk-Backup-Software-4.0.3-Code-Execution.html Source: CCN Type: Full-Disclosure Mailing List, Thu, 31 May 2018 15:26:49 -0300 [CORE-2018-0002] - Quest DR Series Disk Backup Multiple Vulnerabilities Source: FULLDISC Type: Mailing List, Third Party Advisory 20180531 [CORE-2018-0002] - Quest DR Series Disk Backup Multiple Vulnerabilities Source: XF Type: UNKNOWN quest-dr-cve201811170-command-exec(144216) Source: CCN Type: Packet Storm Security [05-31-2018] Quest DR Series Disk Backup Software 4.0.3 Code Execution Source: MISC Type: Technical Description, Third Party Advisory https://www.coresecurity.com/advisories/quest-dr-series-disk-backup-multiple-vulnerabilities Source: CCN Type: Quest Web site DR Series Disk Backup Software | ||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||
BACK |