Back
CVE-2018-1163
CRITICAL
This vulnerability allows remote attackers to bypass authentication on vulnerable installations of Quest NetVault Backup 11.2.0.13. The specific flaw exists within JSON RPC Request handling. By setting the checksession parameter to a specific value, it is possible to bypass authentication to critical functions. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-4752.
Published: Feb 8, 2018
Modified: Jun 17, 2026
CWE-287
NVD-CWE-noinfo
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| quest | netvault_backup | 11.2.0.13 |
GitHub Security Advisory GHSA-4rqj-h9m9-94p6
This vulnerability allows remote attackers to bypass authentication on vulnerable installations...
References (2)
- https://zerodayinitiative.com/advisories/ZDI-18-006 Third Party Advisory, VDB Entry
- https://zerodayinitiative.com/advisories/ZDI-18-006 Third Party Advisory, VDB Entry
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
16.04%
Top 3% most likely to be exploited
Threat Score
44 / 100
Data Sources
NVD
EPSS
GitHub