CVE-2018-11174: OS Command Injection
Published Jun 1, 2018
·Updated
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 32 of 46).
Affected Software
1 affected component
Quest Disk Backup<4.0.3.1
Event History
Jun 1, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-11174?
CVE-2018-11174 is a vulnerability in Quest DR Series Disk Backup software version before 4.0.3.1 that allows command injection.
2
How severe is CVE-2018-11174?
CVE-2018-11174 has a severity rating of 8.8 (high).
3
How does CVE-2018-11174 affect Quest DR Series Disk Backup software?
CVE-2018-11174 affects Quest DR Series Disk Backup software version before 4.0.3.1.
4
What is the Common Weakness Enumeration (CWE) associated with CVE-2018-11174?
CVE-2018-11174 is associated with CWE-77 (Improper Neutralization of Special Elements used in a Command) and CWE-78 (Improper Neutralization of Special Elements used in an OS Command).
5
How can I fix the CVE-2018-11174 vulnerability?
To fix the CVE-2018-11174 vulnerability, update your Quest DR Series Disk Backup software to version 4.0.3.1 or later.