Back to Database
Status published
Critical
CVE-2014-8687
Seagate Business NAS devices with firmware before 2015.00322 allow remote...
Vulnerability Description
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraging use of a static encryption key to create session tokens.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-8687
Credits & Attribution
No credits recorded in the NVD database.
References
- https://beyondbinary.io/articles/seagate-nas-rce/
- http://www.securityfocus.com/bid/72831
- http://packetstormsecurity.com/files/130609/Seagate-Business-NAS-Unauthenticated-Remote-Command-Execution.html
- http://packetstormsecurity.com/files/130585/Seagate-Business-NAS-2014.00319-Remote-Code-Execution.html
- https://www.exploit-db.com/exploits/36202/
- https://www.exploit-db.com/exploits/36264/
More from seagate
View All →CVE-2021-43429
A Denial of Service vulnerability exists in CORTX-S3 Server as...
High
7.5
CVE-2020-6627
The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and...
Unknown
0
CVE-2018-5347
Seagate Media Server in Seagate Personal Cloud has unauthenticated command...
Critical
9.8
CVE-2018-12304
Cross-site scripting in Application Manager in Seagate NAS OS version...
Medium
6.1
CVE-2018-12303
Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1...
Medium
5.4
Affected Vendor
seagate
View all reports →Affected Software
business nas firmware
Vulnerable Versions:
2014.00319
Timeline
Official Publish:
June 8th, 2017
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.