Vulnerabilities
Vulnerable Software
Seagate:  Security Vulnerabilities
The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_helper.php by leveraging the "start" state and sending a check_device_name request.
CVSS Score
9.8
EPSS Score
0.078
Published
2022-12-06
A Denial of Service vulnerability exists in CORTX-S3 Server as of 11/7/2021 via the mempool_destroy method due to a failture to release locks pool->lock.
CVSS Score
7.5
EPSS Score
0.002
Published
2022-04-07
/api/2.0/rest/aggregator/xml in Axentra firmware, used by NETGEAR Stora, Seagate GoFlex Home, and MEDION LifeCloud, has an XXE vulnerability that can be chained with an SSRF bug to gain remote command execution as root. It can be triggered by anyone who knows the IP address of the affected device.
CVSS Score
9.8
EPSS Score
0.155
Published
2019-06-19
SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId URL parameter.
CVSS Score
9.8
EPSS Score
0.003
Published
2019-05-13
Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authentication via empty POST requests.
CVSS Score
7.5
EPSS Score
0.651
Published
2019-05-13
Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names.
CVSS Score
6.1
EPSS Score
0.002
Published
2019-05-13
Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL path.
CVSS Score
7.5
EPSS Score
0.004
Published
2019-05-13
Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names.
CVSS Score
5.4
EPSS Score
0.002
Published
2019-05-13
Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'state' URL parameter.
CVSS Score
6.1
EPSS Score
0.135
Published
2019-05-13
Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL of 127.0.0.1 or localhost.
CVSS Score
7.5
EPSS Score
0.003
Published
2019-05-13


Contact Us

Shodan ® - All rights reserved