CVE-2018-11175: OS Command Injection
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 33 of 46).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11175?
CVE-2018-11175 is a vulnerability in the Quest DR Series Disk Backup software version before 4.0.3.1 that allows command injection.
What is the severity of CVE-2018-11175?
CVE-2018-11175 has a severity score of 8.8, which is considered high.
How does CVE-2018-11175 affect the Quest DR Series Disk Backup software?
CVE-2018-11175 affects Quest DR Series Disk Backup software versions before 4.0.3.1 and allows command injection.
What is the Common Weakness Enumeration (CWE) ID for CVE-2018-11175?
The Common Weakness Enumeration (CWE) IDs for CVE-2018-11175 are CWE-77 (Improper Neutralization of Special Elements used in a Command) and CWE-78 (Improper Neutralization of Special Elements used in an OS Command).
How can I fix the CVE-2018-11175 vulnerability in Quest DR Series Disk Backup software?
To fix the CVE-2018-11175 vulnerability, you should update the Quest DR Series Disk Backup software to version 4.0.3.1 or later.