Skip to content
Noroxi

Seagate records

28 published records for vendor seagate.

All records

28 records
  • Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.p

    CriticalCVSS 9.8Proof of conceptEPSS 54%

    seagate · personal cloud firmwareJan 11, 2018

  • Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or th

    CriticalCVSS 9.8Proof of conceptEPSS 51%

    seagate · blackarmor nas 220 firmwareFeb 23, 2018

  • Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by levera

    CriticalCVSS 9.8WeaponizedEPSS 44%

    seagate · business nas firmwareJun 8, 2017

  • Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters

    CriticalCVSS 9.8Proof of conceptEPSS 15%

    seagate · blackarmor nas 220 firmwareOct 11, 2017

  • The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_b

    CriticalCVSS 9.8Proof of conceptEPSS 13%

    seagate · stcg2000300 firmwareDec 6, 2022

  • /api/2.0/rest/aggregator/xml in Axentra firmware, used by NETGEAR Stora, Seagate GoFlex Home, and MEDION LifeCloud, has an XXE vulnerability

    CriticalCVSS 9.8No exploitEPSS 8%

    axentra · hipservJun 19, 2019

  • d41d8cd98f00b204e9800998ecf8427e.php in the management web server on the Seagate BlackArmor device allows remote attackers to change the adm

    CriticalCVSS 10.0No exploitEPSS 4%

    seagate · blackarmor nasMay 25, 2012

  • Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before

    CriticalCVSS 9.8No exploitEPSS 4%

    seagate · wireless mobile storageDec 31, 2015

  • backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a hard-coded password of '!~@##$$%FREDESWWSED' for a backdoor user.

    CriticalCVSS 9.8No exploitEPSS 3%

    seagate · blackarmor nas 220 firmwareFeb 23, 2018

  • SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId

    CriticalCVSS 9.8No exploitEPSS 1%

    seagate · nas osMay 13, 2019

  • CVE-2015-2876
    36Monitor

    Unrestricted file upload vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, a

    HighCVSS 8.8No exploitEPSS 3%

    seagate · wireless mobile storageDec 31, 2015

  • Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain infor

    HighCVSS 7.5Proof of conceptEPSS 11%

    seagate · nas osMay 13, 2019

  • Seagate Media Server in Seagate Personal Cloud before 4.3.18.4 has directory traversal in getPhotoPlaylistPhotos.psp via a parameter named u

    HighCVSS 7.5No exploitEPSS 4%

    seagate · personal cloud firmwareApr 27, 2018

  • CVE-2015-2875
    31Monitor

    Absolute path traversal vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, an

    HighCVSS 7.5No exploitEPSS 3%

    seagate · goflex satteliteDec 31, 2015

  • Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL pa

    HighCVSS 7.5No exploitEPSS 2%

    seagate · nas osMay 13, 2019

  • Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL

    HighCVSS 7.5No exploitEPSS 1%

    seagate · nas osMay 13, 2019

  • A Denial of Service vulnerability exists in CORTX-S3 Server as of 11/7/2021 via the mempool_destroy method due to a failture to release lock

    HighCVSS 7.5No exploitEPSS 1%

    seagate · cortx-s3 serverApr 7, 2022

  • CVE-2013-6922
    27Monitor

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow re

    MediumCVSS 6.8Proof of conceptEPSS 1%

    seagate · blackarmor nas 220 firmwareJan 21, 2014

  • Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via

    MediumCVSS 6.1Proof of conceptEPSS 3%

    seagate · nas osMay 13, 2019

  • Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple applicati

    MediumCVSS 6.1No exploitEPSS 1%

    seagate · nas osMay 13, 2019

  • Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via

    MediumCVSS 6.1No exploitEPSS 1%

    seagate · nas osMay 13, 2019

  • Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names.

    MediumCVSS 6.1No exploitEPSS 1%

    seagate · nas osMay 13, 2019

  • Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names.

    MediumCVSS 5.4No exploitEPSS 1%

    seagate · nas osMay 13, 2019

  • Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.

    MediumCVSS 5.4No exploitEPSS 1%

    seagate · nas osMay 13, 2019

  • CVE-2013-6923
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attack

    MediumCVSS 4.3Proof of conceptEPSS 3%

    seagate · blackarmor nas 220 firmwareJan 9, 2014