Seagate records
28 published records for vendor seagate.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 3.6%
- Pre-auth RCE
- 8
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-254 7PK - Security Features3
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
The weakness classes this vendor ships most often: where to look.
CWEAll records
28 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
55Plan | CVE-2018-5347Proof of concept | Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.pseagate · personal cloud firmware · CWE-78 | Critical9.8 | — | 54.2% | Jan 11, 2018 |
54Plan | CVE-2014-3206Proof of concept | Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or thseagate · blackarmor nas 220 firmware · CWE-20 | Critical9.8 | — | 51.0% | Feb 23, 2018 |
52Plan | CVE-2014-8687Weaponized | Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraseagate · business nas firmware · CWE-327 | Critical9.8 | — | 43.8% | Jun 8, 2017 |
44Plan | CVE-2013-6924Proof of concept | Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters seagate · blackarmor nas 220 firmware · CWE-77 | Critical9.8 | — | 15.2% | Oct 11, 2017 |
43Plan | CVE-2020-6627Proof of concept | The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_bseagate · stcg2000300 firmware · CWE-78 | Critical9.8 | — | 12.8% | Dec 6, 2022 |
41Plan | CVE-2018-18471No exploit | /api/2.0/rest/aggregator/xml in Axentra firmware, used by NETGEAR Stora, Seagate GoFlex Home, and MEDION LifeCloud, has an XXE vulnerabilityaxentra · hipserv · CWE-611 | Critical9.8 | — | 7.7% | Jun 19, 2019 |
41Plan | CVE-2012-2568No exploit | d41d8cd98f00b204e9800998ecf8427e.php in the management web server on the Seagate BlackArmor device allows remote attackers to change the admseagate · blackarmor nas · CWE-264 | Critical10.0 | — | 4.4% | May 25, 2012 |
40Plan | CVE-2015-2874No exploit | Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware beforeseagate · wireless mobile storage · CWE-255 | Critical9.8 | — | 4.2% | Dec 31, 2015 |
40Plan | CVE-2014-3205No exploit | backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a hard-coded password of '!~@##$$%FREDESWWSED' for a backdoor user.seagate · blackarmor nas 220 firmware · CWE-798 | Critical9.8 | — | 2.7% | Feb 23, 2018 |
39Monitor | CVE-2018-12295No exploit | SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId seagate · nas os · CWE-89 | Critical9.8 | — | 1.1% | May 13, 2019 |
36Monitor | CVE-2015-2876No exploit | Unrestricted file upload vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, aseagate · wireless mobile storage | High8.8 | — | 2.8% | Dec 31, 2015 |
33Monitor | CVE-2018-12296Proof of concept | Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain inforseagate · nas os · CWE-732 | High7.5 | — | 11.3% | May 13, 2019 |
31Monitor | CVE-2017-18263No exploit | Seagate Media Server in Seagate Personal Cloud before 4.3.18.4 has directory traversal in getPhotoPlaylistPhotos.psp via a parameter named useagate · personal cloud firmware · CWE-22 | High7.5 | — | 3.5% | Apr 27, 2018 |
31Monitor | CVE-2015-2875No exploit | Absolute path traversal vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, anseagate · goflex sattelite · CWE-22 | High7.5 | — | 3.2% | Dec 31, 2015 |
31Monitor | CVE-2018-12298No exploit | Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL paseagate · nas os · CWE-22 | High7.5 | — | 1.7% | May 13, 2019 |
30Monitor | CVE-2018-12301No exploit | Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL seagate · nas os · CWE-200 | High7.5 | — | 1.4% | May 13, 2019 |
30Monitor | CVE-2021-43429No exploit | A Denial of Service vulnerability exists in CORTX-S3 Server as of 11/7/2021 via the mempool_destroy method due to a failture to release lockseagate · cortx-s3 server · CWE-667 | High7.5 | — | 0.9% | Apr 7, 2022 |
27Monitor | CVE-2013-6922Proof of concept | Multiple cross-site request forgery (CSRF) vulnerabilities in the Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow reseagate · blackarmor nas 220 firmware · CWE-352 | Medium6.8 | — | 1.4% | Jan 21, 2014 |
25Monitor | CVE-2018-12300Proof of concept | Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header viaseagate · nas os · CWE-601 | Medium6.1 | — | 3.1% | May 13, 2019 |
24Monitor | CVE-2018-12304No exploit | Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple applicatiseagate · nas os · CWE-79 | Medium6.1 | — | 0.8% | May 13, 2019 |
24Monitor | CVE-2018-12302No exploit | Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens viaseagate · nas os · CWE-79 | Medium6.1 | — | 0.8% | May 13, 2019 |
24Monitor | CVE-2018-12297No exploit | Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names.seagate · nas os · CWE-79 | Medium6.1 | — | 0.7% | May 13, 2019 |
21Monitor | CVE-2018-12299No exploit | Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names.seagate · nas os · CWE-79 | Medium5.4 | — | 0.6% | May 13, 2019 |
21Monitor | CVE-2018-12303No exploit | Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.seagate · nas os · CWE-79 | Medium5.4 | — | 0.6% | May 13, 2019 |
18Monitor | CVE-2013-6923Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attackseagate · blackarmor nas 220 firmware · CWE-79 | Medium4.3 | — | 3.2% | Jan 9, 2014 |
- CVE-2018-534755Plan
Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.p
CriticalCVSS 9.8Proof of conceptEPSS 54%seagate · personal cloud firmwareJan 11, 2018
- CVE-2014-320654Plan
Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or th
CriticalCVSS 9.8Proof of conceptEPSS 51%seagate · blackarmor nas 220 firmwareFeb 23, 2018
- CVE-2014-868752Plan
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by levera
CriticalCVSS 9.8WeaponizedEPSS 44%seagate · business nas firmwareJun 8, 2017
- CVE-2013-692444Plan
Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters
CriticalCVSS 9.8Proof of conceptEPSS 15%seagate · blackarmor nas 220 firmwareOct 11, 2017
- CVE-2020-662743Plan
The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_b
CriticalCVSS 9.8Proof of conceptEPSS 13%seagate · stcg2000300 firmwareDec 6, 2022
- CVE-2018-1847141Plan
/api/2.0/rest/aggregator/xml in Axentra firmware, used by NETGEAR Stora, Seagate GoFlex Home, and MEDION LifeCloud, has an XXE vulnerability
CriticalCVSS 9.8No exploitEPSS 8%axentra · hipservJun 19, 2019
- CVE-2012-256841Plan
d41d8cd98f00b204e9800998ecf8427e.php in the management web server on the Seagate BlackArmor device allows remote attackers to change the adm
CriticalCVSS 10.0No exploitEPSS 4%seagate · blackarmor nasMay 25, 2012
- CVE-2015-287440Plan
Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before
CriticalCVSS 9.8No exploitEPSS 4%seagate · wireless mobile storageDec 31, 2015
- CVE-2014-320540Plan
backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a hard-coded password of '!~@##$$%FREDESWWSED' for a backdoor user.
CriticalCVSS 9.8No exploitEPSS 3%seagate · blackarmor nas 220 firmwareFeb 23, 2018
- CVE-2018-1229539Monitor
SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId
CriticalCVSS 9.8No exploitEPSS 1%seagate · nas osMay 13, 2019
- CVE-2015-287636Monitor
Unrestricted file upload vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, a
HighCVSS 8.8No exploitEPSS 3%seagate · wireless mobile storageDec 31, 2015
- CVE-2018-1229633Monitor
Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain infor
HighCVSS 7.5Proof of conceptEPSS 11%seagate · nas osMay 13, 2019
- CVE-2017-1826331Monitor
Seagate Media Server in Seagate Personal Cloud before 4.3.18.4 has directory traversal in getPhotoPlaylistPhotos.psp via a parameter named u
HighCVSS 7.5No exploitEPSS 4%seagate · personal cloud firmwareApr 27, 2018
- CVE-2015-287531Monitor
Absolute path traversal vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, an
HighCVSS 7.5No exploitEPSS 3%seagate · goflex satteliteDec 31, 2015
- CVE-2018-1229831Monitor
Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL pa
HighCVSS 7.5No exploitEPSS 2%seagate · nas osMay 13, 2019
- CVE-2018-1230130Monitor
Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL
HighCVSS 7.5No exploitEPSS 1%seagate · nas osMay 13, 2019
- CVE-2021-4342930Monitor
A Denial of Service vulnerability exists in CORTX-S3 Server as of 11/7/2021 via the mempool_destroy method due to a failture to release lock
HighCVSS 7.5No exploitEPSS 1%seagate · cortx-s3 serverApr 7, 2022
- CVE-2013-692227Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities in the Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow re
MediumCVSS 6.8Proof of conceptEPSS 1%seagate · blackarmor nas 220 firmwareJan 21, 2014
- CVE-2018-1230025Monitor
Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via
MediumCVSS 6.1Proof of conceptEPSS 3%seagate · nas osMay 13, 2019
- CVE-2018-1230424Monitor
Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple applicati
MediumCVSS 6.1No exploitEPSS 1%seagate · nas osMay 13, 2019
- CVE-2018-1230224Monitor
Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via
MediumCVSS 6.1No exploitEPSS 1%seagate · nas osMay 13, 2019
- CVE-2018-1229724Monitor
Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names.
MediumCVSS 6.1No exploitEPSS 1%seagate · nas osMay 13, 2019
- CVE-2018-1229921Monitor
Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names.
MediumCVSS 5.4No exploitEPSS 1%seagate · nas osMay 13, 2019
- CVE-2018-1230321Monitor
Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.
MediumCVSS 5.4No exploitEPSS 1%seagate · nas osMay 13, 2019
- CVE-2013-692318Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attack
MediumCVSS 4.3Proof of conceptEPSS 3%seagate · blackarmor nas 220 firmwareJan 9, 2014