Перейти к содержимому
Noroxi

Записи Seagate

28 опубликованных записей вендора seagate.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
1 · 3,6 %
Pre-auth RCE
8
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

28 записей
  • CVE-2018-5347
    55В плане

    Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.p

    КритическаяCVSS 9,8Proof of conceptEPSS 54 %

    seagate · personal cloud firmware11 янв. 2018 г.

  • CVE-2014-3206
    54В плане

    Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or th

    КритическаяCVSS 9,8Proof of conceptEPSS 51 %

    seagate · blackarmor nas 220 firmware23 февр. 2018 г.

  • CVE-2014-8687
    52В плане

    Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by levera

    КритическаяCVSS 9,8Готовый эксплойтEPSS 44 %

    seagate · business nas firmware8 июн. 2017 г.

  • CVE-2013-6924
    44В плане

    Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters

    КритическаяCVSS 9,8Proof of conceptEPSS 15 %

    seagate · blackarmor nas 220 firmware11 окт. 2017 г.

  • CVE-2020-6627
    43В плане

    The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_b

    КритическаяCVSS 9,8Proof of conceptEPSS 13 %

    seagate · stcg2000300 firmware6 дек. 2022 г.

  • CVE-2018-18471
    41В плане

    /api/2.0/rest/aggregator/xml in Axentra firmware, used by NETGEAR Stora, Seagate GoFlex Home, and MEDION LifeCloud, has an XXE vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 8 %

    axentra · hipserv19 июн. 2019 г.

  • CVE-2012-2568
    41В плане

    d41d8cd98f00b204e9800998ecf8427e.php in the management web server on the Seagate BlackArmor device allows remote attackers to change the adm

    КритическаяCVSS 10,0Эксплойта нетEPSS 4 %

    seagate · blackarmor nas25 мая 2012 г.

  • CVE-2015-2874
    40В плане

    Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    seagate · wireless mobile storage31 дек. 2015 г.

  • CVE-2014-3205
    40В плане

    backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a hard-coded password of '!~@##$$%FREDESWWSED' for a backdoor user.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    seagate · blackarmor nas 220 firmware23 февр. 2018 г.

  • CVE-2018-12295
    39Наблюдать

    SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    seagate · nas os13 мая 2019 г.

  • CVE-2015-2876
    36Наблюдать

    Unrestricted file upload vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, a

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    seagate · wireless mobile storage31 дек. 2015 г.

  • CVE-2018-12296
    33Наблюдать

    Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain infor

    ВысокаяCVSS 7,5Proof of conceptEPSS 11 %

    seagate · nas os13 мая 2019 г.

  • CVE-2017-18263
    31Наблюдать

    Seagate Media Server in Seagate Personal Cloud before 4.3.18.4 has directory traversal in getPhotoPlaylistPhotos.psp via a parameter named u

    ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %

    seagate · personal cloud firmware27 апр. 2018 г.

  • CVE-2015-2875
    31Наблюдать

    Absolute path traversal vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, an

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    seagate · goflex sattelite31 дек. 2015 г.

  • CVE-2018-12298
    31Наблюдать

    Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL pa

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    seagate · nas os13 мая 2019 г.

  • CVE-2018-12301
    30Наблюдать

    Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    seagate · nas os13 мая 2019 г.

  • CVE-2021-43429
    30Наблюдать

    A Denial of Service vulnerability exists in CORTX-S3 Server as of 11/7/2021 via the mempool_destroy method due to a failture to release lock

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    seagate · cortx-s3 server7 апр. 2022 г.

  • CVE-2013-6922
    27Наблюдать

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow re

    СредняяCVSS 6,8Proof of conceptEPSS 1 %

    seagate · blackarmor nas 220 firmware21 янв. 2014 г.

  • CVE-2018-12300
    25Наблюдать

    Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via

    СредняяCVSS 6,1Proof of conceptEPSS 3 %

    seagate · nas os13 мая 2019 г.

  • CVE-2018-12304
    24Наблюдать

    Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple applicati

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    seagate · nas os13 мая 2019 г.

  • CVE-2018-12302
    24Наблюдать

    Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    seagate · nas os13 мая 2019 г.

  • CVE-2018-12297
    24Наблюдать

    Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    seagate · nas os13 мая 2019 г.

  • CVE-2018-12299
    21Наблюдать

    Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names.

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    seagate · nas os13 мая 2019 г.

  • CVE-2018-12303
    21Наблюдать

    Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    seagate · nas os13 мая 2019 г.

  • CVE-2013-6923
    18Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attack

    СредняяCVSS 4,3Proof of conceptEPSS 3 %

    seagate · blackarmor nas 220 firmware9 янв. 2014 г.