İçeriğe atla
Noroxi

Seagate kayıtları

seagate üreticisine ait 28 yayımlanmış kayıt.

Tüm kayıtlar

28 kayıt
  • CVE-2018-5347
    55Planlayın

    Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.p

    KritikCVSS 9,8Kavram kanıtıEPSS %54

    seagate · personal cloud firmware11 Oca 2018

  • CVE-2014-3206
    54Planlayın

    Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or th

    KritikCVSS 9,8Kavram kanıtıEPSS %51

    seagate · blackarmor nas 220 firmware23 Şub 2018

  • CVE-2014-8687
    52Planlayın

    Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by levera

    KritikCVSS 9,8SilahlaştırılmışEPSS %44

    seagate · business nas firmware8 Haz 2017

  • CVE-2013-6924
    44Planlayın

    Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters

    KritikCVSS 9,8Kavram kanıtıEPSS %15

    seagate · blackarmor nas 220 firmware11 Eki 2017

  • CVE-2020-6627
    43Planlayın

    The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_b

    KritikCVSS 9,8Kavram kanıtıEPSS %13

    seagate · stcg2000300 firmware6 Ara 2022

  • CVE-2018-18471
    41Planlayın

    /api/2.0/rest/aggregator/xml in Axentra firmware, used by NETGEAR Stora, Seagate GoFlex Home, and MEDION LifeCloud, has an XXE vulnerability

    KritikCVSS 9,8İstismar yokEPSS %8

    axentra · hipserv19 Haz 2019

  • CVE-2012-2568
    41Planlayın

    d41d8cd98f00b204e9800998ecf8427e.php in the management web server on the Seagate BlackArmor device allows remote attackers to change the adm

    KritikCVSS 10,0İstismar yokEPSS %4

    seagate · blackarmor nas25 May 2012

  • CVE-2015-2874
    40Planlayın

    Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before

    KritikCVSS 9,8İstismar yokEPSS %4

    seagate · wireless mobile storage31 Ara 2015

  • CVE-2014-3205
    40Planlayın

    backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a hard-coded password of '!~@##$$%FREDESWWSED' for a backdoor user.

    KritikCVSS 9,8İstismar yokEPSS %3

    seagate · blackarmor nas 220 firmware23 Şub 2018

  • CVE-2018-12295
    39İzleyin

    SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId

    KritikCVSS 9,8İstismar yokEPSS %1

    seagate · nas os13 May 2019

  • CVE-2015-2876
    36İzleyin

    Unrestricted file upload vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, a

    YüksekCVSS 8,8İstismar yokEPSS %3

    seagate · wireless mobile storage31 Ara 2015

  • CVE-2018-12296
    33İzleyin

    Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain infor

    YüksekCVSS 7,5Kavram kanıtıEPSS %11

    seagate · nas os13 May 2019

  • CVE-2017-18263
    31İzleyin

    Seagate Media Server in Seagate Personal Cloud before 4.3.18.4 has directory traversal in getPhotoPlaylistPhotos.psp via a parameter named u

    YüksekCVSS 7,5İstismar yokEPSS %4

    seagate · personal cloud firmware27 Nis 2018

  • CVE-2015-2875
    31İzleyin

    Absolute path traversal vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, an

    YüksekCVSS 7,5İstismar yokEPSS %3

    seagate · goflex sattelite31 Ara 2015

  • CVE-2018-12298
    31İzleyin

    Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL pa

    YüksekCVSS 7,5İstismar yokEPSS %2

    seagate · nas os13 May 2019

  • CVE-2018-12301
    30İzleyin

    Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL

    YüksekCVSS 7,5İstismar yokEPSS %1

    seagate · nas os13 May 2019

  • CVE-2021-43429
    30İzleyin

    A Denial of Service vulnerability exists in CORTX-S3 Server as of 11/7/2021 via the mempool_destroy method due to a failture to release lock

    YüksekCVSS 7,5İstismar yokEPSS %1

    seagate · cortx-s3 server7 Nis 2022

  • CVE-2013-6922
    27İzleyin

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow re

    OrtaCVSS 6,8Kavram kanıtıEPSS %1

    seagate · blackarmor nas 220 firmware21 Oca 2014

  • CVE-2018-12300
    25İzleyin

    Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via

    OrtaCVSS 6,1Kavram kanıtıEPSS %3

    seagate · nas os13 May 2019

  • CVE-2018-12304
    24İzleyin

    Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple applicati

    OrtaCVSS 6,1İstismar yokEPSS %1

    seagate · nas os13 May 2019

  • CVE-2018-12302
    24İzleyin

    Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via

    OrtaCVSS 6,1İstismar yokEPSS %1

    seagate · nas os13 May 2019

  • CVE-2018-12297
    24İzleyin

    Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names.

    OrtaCVSS 6,1İstismar yokEPSS %1

    seagate · nas os13 May 2019

  • CVE-2018-12299
    21İzleyin

    Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names.

    OrtaCVSS 5,4İstismar yokEPSS %1

    seagate · nas os13 May 2019

  • CVE-2018-12303
    21İzleyin

    Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.

    OrtaCVSS 5,4İstismar yokEPSS %1

    seagate · nas os13 May 2019

  • CVE-2013-6923
    18İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attack

    OrtaCVSS 4,3Kavram kanıtıEPSS %3

    seagate · blackarmor nas 220 firmware9 Oca 2014