Записи Seagate
28 опубликованных записей вендора seagate.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 3,6 %
- Pre-auth RCE
- 8
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-254 7PK - Security Features3
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
28 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
55В плане | CVE-2018-5347Proof of concept | Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.pseagate · personal cloud firmware · CWE-78 | Критическая9,8 | — | 54,2 % | 11 янв. 2018 г. |
54В плане | CVE-2014-3206Proof of concept | Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or thseagate · blackarmor nas 220 firmware · CWE-20 | Критическая9,8 | — | 51,0 % | 23 февр. 2018 г. |
52В плане | CVE-2014-8687Готовый эксплойт | Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraseagate · business nas firmware · CWE-327 | Критическая9,8 | — | 43,8 % | 8 июн. 2017 г. |
44В плане | CVE-2013-6924Proof of concept | Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters seagate · blackarmor nas 220 firmware · CWE-77 | Критическая9,8 | — | 15,2 % | 11 окт. 2017 г. |
43В плане | CVE-2020-6627Proof of concept | The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_bseagate · stcg2000300 firmware · CWE-78 | Критическая9,8 | — | 12,8 % | 6 дек. 2022 г. |
41В плане | CVE-2018-18471Эксплойта нет | /api/2.0/rest/aggregator/xml in Axentra firmware, used by NETGEAR Stora, Seagate GoFlex Home, and MEDION LifeCloud, has an XXE vulnerabilityaxentra · hipserv · CWE-611 | Критическая9,8 | — | 7,7 % | 19 июн. 2019 г. |
41В плане | CVE-2012-2568Эксплойта нет | d41d8cd98f00b204e9800998ecf8427e.php in the management web server on the Seagate BlackArmor device allows remote attackers to change the admseagate · blackarmor nas · CWE-264 | Критическая10,0 | — | 4,4 % | 25 мая 2012 г. |
40В плане | CVE-2015-2874Эксплойта нет | Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware beforeseagate · wireless mobile storage · CWE-255 | Критическая9,8 | — | 4,2 % | 31 дек. 2015 г. |
40В плане | CVE-2014-3205Эксплойта нет | backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a hard-coded password of '!~@##$$%FREDESWWSED' for a backdoor user.seagate · blackarmor nas 220 firmware · CWE-798 | Критическая9,8 | — | 2,7 % | 23 февр. 2018 г. |
39Наблюдать | CVE-2018-12295Эксплойта нет | SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId seagate · nas os · CWE-89 | Критическая9,8 | — | 1,1 % | 13 мая 2019 г. |
36Наблюдать | CVE-2015-2876Эксплойта нет | Unrestricted file upload vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, aseagate · wireless mobile storage | Высокая8,8 | — | 2,8 % | 31 дек. 2015 г. |
33Наблюдать | CVE-2018-12296Proof of concept | Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain inforseagate · nas os · CWE-732 | Высокая7,5 | — | 11,3 % | 13 мая 2019 г. |
31Наблюдать | CVE-2017-18263Эксплойта нет | Seagate Media Server in Seagate Personal Cloud before 4.3.18.4 has directory traversal in getPhotoPlaylistPhotos.psp via a parameter named useagate · personal cloud firmware · CWE-22 | Высокая7,5 | — | 3,5 % | 27 апр. 2018 г. |
31Наблюдать | CVE-2015-2875Эксплойта нет | Absolute path traversal vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, anseagate · goflex sattelite · CWE-22 | Высокая7,5 | — | 3,2 % | 31 дек. 2015 г. |
31Наблюдать | CVE-2018-12298Эксплойта нет | Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL paseagate · nas os · CWE-22 | Высокая7,5 | — | 1,7 % | 13 мая 2019 г. |
30Наблюдать | CVE-2018-12301Эксплойта нет | Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL seagate · nas os · CWE-200 | Высокая7,5 | — | 1,4 % | 13 мая 2019 г. |
30Наблюдать | CVE-2021-43429Эксплойта нет | A Denial of Service vulnerability exists in CORTX-S3 Server as of 11/7/2021 via the mempool_destroy method due to a failture to release lockseagate · cortx-s3 server · CWE-667 | Высокая7,5 | — | 0,9 % | 7 апр. 2022 г. |
27Наблюдать | CVE-2013-6922Proof of concept | Multiple cross-site request forgery (CSRF) vulnerabilities in the Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow reseagate · blackarmor nas 220 firmware · CWE-352 | Средняя6,8 | — | 1,4 % | 21 янв. 2014 г. |
25Наблюдать | CVE-2018-12300Proof of concept | Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header viaseagate · nas os · CWE-601 | Средняя6,1 | — | 3,1 % | 13 мая 2019 г. |
24Наблюдать | CVE-2018-12304Эксплойта нет | Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple applicatiseagate · nas os · CWE-79 | Средняя6,1 | — | 0,8 % | 13 мая 2019 г. |
24Наблюдать | CVE-2018-12302Эксплойта нет | Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens viaseagate · nas os · CWE-79 | Средняя6,1 | — | 0,8 % | 13 мая 2019 г. |
24Наблюдать | CVE-2018-12297Эксплойта нет | Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names.seagate · nas os · CWE-79 | Средняя6,1 | — | 0,7 % | 13 мая 2019 г. |
21Наблюдать | CVE-2018-12299Эксплойта нет | Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names.seagate · nas os · CWE-79 | Средняя5,4 | — | 0,6 % | 13 мая 2019 г. |
21Наблюдать | CVE-2018-12303Эксплойта нет | Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.seagate · nas os · CWE-79 | Средняя5,4 | — | 0,6 % | 13 мая 2019 г. |
18Наблюдать | CVE-2013-6923Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attackseagate · blackarmor nas 220 firmware · CWE-79 | Средняя4,3 | — | 3,2 % | 9 янв. 2014 г. |
- CVE-2018-534755В плане
Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.p
КритическаяCVSS 9,8Proof of conceptEPSS 54 %seagate · personal cloud firmware11 янв. 2018 г.
- CVE-2014-320654В плане
Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or th
КритическаяCVSS 9,8Proof of conceptEPSS 51 %seagate · blackarmor nas 220 firmware23 февр. 2018 г.
- CVE-2014-868752В плане
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by levera
КритическаяCVSS 9,8Готовый эксплойтEPSS 44 %seagate · business nas firmware8 июн. 2017 г.
- CVE-2013-692444В плане
Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters
КритическаяCVSS 9,8Proof of conceptEPSS 15 %seagate · blackarmor nas 220 firmware11 окт. 2017 г.
- CVE-2020-662743В плане
The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_b
КритическаяCVSS 9,8Proof of conceptEPSS 13 %seagate · stcg2000300 firmware6 дек. 2022 г.
- CVE-2018-1847141В плане
/api/2.0/rest/aggregator/xml in Axentra firmware, used by NETGEAR Stora, Seagate GoFlex Home, and MEDION LifeCloud, has an XXE vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %axentra · hipserv19 июн. 2019 г.
- CVE-2012-256841В плане
d41d8cd98f00b204e9800998ecf8427e.php in the management web server on the Seagate BlackArmor device allows remote attackers to change the adm
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %seagate · blackarmor nas25 мая 2012 г.
- CVE-2015-287440В плане
Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %seagate · wireless mobile storage31 дек. 2015 г.
- CVE-2014-320540В плане
backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a hard-coded password of '!~@##$$%FREDESWWSED' for a backdoor user.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %seagate · blackarmor nas 220 firmware23 февр. 2018 г.
- CVE-2018-1229539Наблюдать
SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %seagate · nas os13 мая 2019 г.
- CVE-2015-287636Наблюдать
Unrestricted file upload vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, a
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %seagate · wireless mobile storage31 дек. 2015 г.
- CVE-2018-1229633Наблюдать
Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain infor
ВысокаяCVSS 7,5Proof of conceptEPSS 11 %seagate · nas os13 мая 2019 г.
- CVE-2017-1826331Наблюдать
Seagate Media Server in Seagate Personal Cloud before 4.3.18.4 has directory traversal in getPhotoPlaylistPhotos.psp via a parameter named u
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %seagate · personal cloud firmware27 апр. 2018 г.
- CVE-2015-287531Наблюдать
Absolute path traversal vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, an
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %seagate · goflex sattelite31 дек. 2015 г.
- CVE-2018-1229831Наблюдать
Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL pa
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %seagate · nas os13 мая 2019 г.
- CVE-2018-1230130Наблюдать
Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %seagate · nas os13 мая 2019 г.
- CVE-2021-4342930Наблюдать
A Denial of Service vulnerability exists in CORTX-S3 Server as of 11/7/2021 via the mempool_destroy method due to a failture to release lock
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %seagate · cortx-s3 server7 апр. 2022 г.
- CVE-2013-692227Наблюдать
Multiple cross-site request forgery (CSRF) vulnerabilities in the Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow re
СредняяCVSS 6,8Proof of conceptEPSS 1 %seagate · blackarmor nas 220 firmware21 янв. 2014 г.
- CVE-2018-1230025Наблюдать
Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via
СредняяCVSS 6,1Proof of conceptEPSS 3 %seagate · nas os13 мая 2019 г.
- CVE-2018-1230424Наблюдать
Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple applicati
СредняяCVSS 6,1Эксплойта нетEPSS 1 %seagate · nas os13 мая 2019 г.
- CVE-2018-1230224Наблюдать
Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via
СредняяCVSS 6,1Эксплойта нетEPSS 1 %seagate · nas os13 мая 2019 г.
- CVE-2018-1229724Наблюдать
Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %seagate · nas os13 мая 2019 г.
- CVE-2018-1229921Наблюдать
Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %seagate · nas os13 мая 2019 г.
- CVE-2018-1230321Наблюдать
Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %seagate · nas os13 мая 2019 г.
- CVE-2013-692318Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attack
СредняяCVSS 4,3Proof of conceptEPSS 3 %seagate · blackarmor nas 220 firmware9 янв. 2014 г.