Seagate kayıtları
seagate üreticisine ait 28 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %3,6
- Pre-auth RCE
- 8
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-254 7PK - Security Features3
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
28 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
55Planlayın | CVE-2018-5347Kavram kanıtı | Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.pseagate · personal cloud firmware · CWE-78 | Kritik9,8 | — | %54,2 | 11 Oca 2018 |
54Planlayın | CVE-2014-3206Kavram kanıtı | Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or thseagate · blackarmor nas 220 firmware · CWE-20 | Kritik9,8 | — | %51,0 | 23 Şub 2018 |
52Planlayın | CVE-2014-8687Silahlaştırılmış | Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraseagate · business nas firmware · CWE-327 | Kritik9,8 | — | %43,8 | 8 Haz 2017 |
44Planlayın | CVE-2013-6924Kavram kanıtı | Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters seagate · blackarmor nas 220 firmware · CWE-77 | Kritik9,8 | — | %15,2 | 11 Eki 2017 |
43Planlayın | CVE-2020-6627Kavram kanıtı | The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_bseagate · stcg2000300 firmware · CWE-78 | Kritik9,8 | — | %12,8 | 6 Ara 2022 |
41Planlayın | CVE-2018-18471İstismar yok | /api/2.0/rest/aggregator/xml in Axentra firmware, used by NETGEAR Stora, Seagate GoFlex Home, and MEDION LifeCloud, has an XXE vulnerabilityaxentra · hipserv · CWE-611 | Kritik9,8 | — | %7,7 | 19 Haz 2019 |
41Planlayın | CVE-2012-2568İstismar yok | d41d8cd98f00b204e9800998ecf8427e.php in the management web server on the Seagate BlackArmor device allows remote attackers to change the admseagate · blackarmor nas · CWE-264 | Kritik10,0 | — | %4,4 | 25 May 2012 |
40Planlayın | CVE-2015-2874İstismar yok | Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware beforeseagate · wireless mobile storage · CWE-255 | Kritik9,8 | — | %4,2 | 31 Ara 2015 |
40Planlayın | CVE-2014-3205İstismar yok | backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a hard-coded password of '!~@##$$%FREDESWWSED' for a backdoor user.seagate · blackarmor nas 220 firmware · CWE-798 | Kritik9,8 | — | %2,7 | 23 Şub 2018 |
39İzleyin | CVE-2018-12295İstismar yok | SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId seagate · nas os · CWE-89 | Kritik9,8 | — | %1,1 | 13 May 2019 |
36İzleyin | CVE-2015-2876İstismar yok | Unrestricted file upload vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, aseagate · wireless mobile storage | Yüksek8,8 | — | %2,8 | 31 Ara 2015 |
33İzleyin | CVE-2018-12296Kavram kanıtı | Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain inforseagate · nas os · CWE-732 | Yüksek7,5 | — | %11,3 | 13 May 2019 |
31İzleyin | CVE-2017-18263İstismar yok | Seagate Media Server in Seagate Personal Cloud before 4.3.18.4 has directory traversal in getPhotoPlaylistPhotos.psp via a parameter named useagate · personal cloud firmware · CWE-22 | Yüksek7,5 | — | %3,5 | 27 Nis 2018 |
31İzleyin | CVE-2015-2875İstismar yok | Absolute path traversal vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, anseagate · goflex sattelite · CWE-22 | Yüksek7,5 | — | %3,2 | 31 Ara 2015 |
31İzleyin | CVE-2018-12298İstismar yok | Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL paseagate · nas os · CWE-22 | Yüksek7,5 | — | %1,7 | 13 May 2019 |
30İzleyin | CVE-2018-12301İstismar yok | Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL seagate · nas os · CWE-200 | Yüksek7,5 | — | %1,4 | 13 May 2019 |
30İzleyin | CVE-2021-43429İstismar yok | A Denial of Service vulnerability exists in CORTX-S3 Server as of 11/7/2021 via the mempool_destroy method due to a failture to release lockseagate · cortx-s3 server · CWE-667 | Yüksek7,5 | — | %0,9 | 7 Nis 2022 |
27İzleyin | CVE-2013-6922Kavram kanıtı | Multiple cross-site request forgery (CSRF) vulnerabilities in the Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow reseagate · blackarmor nas 220 firmware · CWE-352 | Orta6,8 | — | %1,4 | 21 Oca 2014 |
25İzleyin | CVE-2018-12300Kavram kanıtı | Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header viaseagate · nas os · CWE-601 | Orta6,1 | — | %3,1 | 13 May 2019 |
24İzleyin | CVE-2018-12304İstismar yok | Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple applicatiseagate · nas os · CWE-79 | Orta6,1 | — | %0,8 | 13 May 2019 |
24İzleyin | CVE-2018-12302İstismar yok | Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens viaseagate · nas os · CWE-79 | Orta6,1 | — | %0,8 | 13 May 2019 |
24İzleyin | CVE-2018-12297İstismar yok | Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names.seagate · nas os · CWE-79 | Orta6,1 | — | %0,7 | 13 May 2019 |
21İzleyin | CVE-2018-12299İstismar yok | Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names.seagate · nas os · CWE-79 | Orta5,4 | — | %0,6 | 13 May 2019 |
21İzleyin | CVE-2018-12303İstismar yok | Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.seagate · nas os · CWE-79 | Orta5,4 | — | %0,6 | 13 May 2019 |
18İzleyin | CVE-2013-6923Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attackseagate · blackarmor nas 220 firmware · CWE-79 | Orta4,3 | — | %3,2 | 9 Oca 2014 |
- CVE-2018-534755Planlayın
Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.p
KritikCVSS 9,8Kavram kanıtıEPSS %54seagate · personal cloud firmware11 Oca 2018
- CVE-2014-320654Planlayın
Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or th
KritikCVSS 9,8Kavram kanıtıEPSS %51seagate · blackarmor nas 220 firmware23 Şub 2018
- CVE-2014-868752Planlayın
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by levera
KritikCVSS 9,8SilahlaştırılmışEPSS %44seagate · business nas firmware8 Haz 2017
- CVE-2013-692444Planlayın
Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters
KritikCVSS 9,8Kavram kanıtıEPSS %15seagate · blackarmor nas 220 firmware11 Eki 2017
- CVE-2020-662743Planlayın
The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_b
KritikCVSS 9,8Kavram kanıtıEPSS %13seagate · stcg2000300 firmware6 Ara 2022
- CVE-2018-1847141Planlayın
/api/2.0/rest/aggregator/xml in Axentra firmware, used by NETGEAR Stora, Seagate GoFlex Home, and MEDION LifeCloud, has an XXE vulnerability
KritikCVSS 9,8İstismar yokEPSS %8axentra · hipserv19 Haz 2019
- CVE-2012-256841Planlayın
d41d8cd98f00b204e9800998ecf8427e.php in the management web server on the Seagate BlackArmor device allows remote attackers to change the adm
KritikCVSS 10,0İstismar yokEPSS %4seagate · blackarmor nas25 May 2012
- CVE-2015-287440Planlayın
Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before
KritikCVSS 9,8İstismar yokEPSS %4seagate · wireless mobile storage31 Ara 2015
- CVE-2014-320540Planlayın
backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a hard-coded password of '!~@##$$%FREDESWWSED' for a backdoor user.
KritikCVSS 9,8İstismar yokEPSS %3seagate · blackarmor nas 220 firmware23 Şub 2018
- CVE-2018-1229539İzleyin
SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId
KritikCVSS 9,8İstismar yokEPSS %1seagate · nas os13 May 2019
- CVE-2015-287636İzleyin
Unrestricted file upload vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, a
YüksekCVSS 8,8İstismar yokEPSS %3seagate · wireless mobile storage31 Ara 2015
- CVE-2018-1229633İzleyin
Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain infor
YüksekCVSS 7,5Kavram kanıtıEPSS %11seagate · nas os13 May 2019
- CVE-2017-1826331İzleyin
Seagate Media Server in Seagate Personal Cloud before 4.3.18.4 has directory traversal in getPhotoPlaylistPhotos.psp via a parameter named u
YüksekCVSS 7,5İstismar yokEPSS %4seagate · personal cloud firmware27 Nis 2018
- CVE-2015-287531İzleyin
Absolute path traversal vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, an
YüksekCVSS 7,5İstismar yokEPSS %3seagate · goflex sattelite31 Ara 2015
- CVE-2018-1229831İzleyin
Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL pa
YüksekCVSS 7,5İstismar yokEPSS %2seagate · nas os13 May 2019
- CVE-2018-1230130İzleyin
Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL
YüksekCVSS 7,5İstismar yokEPSS %1seagate · nas os13 May 2019
- CVE-2021-4342930İzleyin
A Denial of Service vulnerability exists in CORTX-S3 Server as of 11/7/2021 via the mempool_destroy method due to a failture to release lock
YüksekCVSS 7,5İstismar yokEPSS %1seagate · cortx-s3 server7 Nis 2022
- CVE-2013-692227İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in the Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow re
OrtaCVSS 6,8Kavram kanıtıEPSS %1seagate · blackarmor nas 220 firmware21 Oca 2014
- CVE-2018-1230025İzleyin
Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via
OrtaCVSS 6,1Kavram kanıtıEPSS %3seagate · nas os13 May 2019
- CVE-2018-1230424İzleyin
Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple applicati
OrtaCVSS 6,1İstismar yokEPSS %1seagate · nas os13 May 2019
- CVE-2018-1230224İzleyin
Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via
OrtaCVSS 6,1İstismar yokEPSS %1seagate · nas os13 May 2019
- CVE-2018-1229724İzleyin
Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names.
OrtaCVSS 6,1İstismar yokEPSS %1seagate · nas os13 May 2019
- CVE-2018-1229921İzleyin
Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names.
OrtaCVSS 5,4İstismar yokEPSS %1seagate · nas os13 May 2019
- CVE-2018-1230321İzleyin
Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.
OrtaCVSS 5,4İstismar yokEPSS %1seagate · nas os13 May 2019
- CVE-2013-692318İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attack
OrtaCVSS 4,3Kavram kanıtıEPSS %3seagate · blackarmor nas 220 firmware9 Oca 2014