First published: Sat Jun 02 2018(Updated: )
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 31 of 46).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Quest Disk Backup | <4.0.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-11173 is high with a CVSS score of 8.8.
CVE-2018-11173 is a command injection vulnerability in Quest DR Series Disk Backup software version before 4.0.3.1, allowing an attacker to execute arbitrary commands.
Quest DR Series Disk Backup software versions up to and excluding 4.0.3.1 are affected by CVE-2018-11173.
Upgrade to Quest DR Series Disk Backup software version 4.0.3.1 or later to fix CVE-2018-11173.
For more information about CVE-2018-11173, refer to the following references: [PacketStormSecurity](http://packetstormsecurity.com/files/148003/Quest-DR-Series-Disk-Backup-Software-4.0.3-Code-Execution.html), [SecLists](http://seclists.org/fulldisclosure/2018/May/71), [Core Security](https://www.coresecurity.com/advisories/quest-dr-series-disk-backup-multiple-vulnerabilities)