← Back

Seagate

seagate

27 CVEs • 25 products

Products (25)

Click to collapse
Toggle
Nas Os
nas_os
Blackarmor Nas
blackarmor_nas
Business Nas
business_nas
St500lt015
st500lt015
St500lt025
st500lt025
Goflex Home
goflex_home
Stcg2000300
stcg2000300
Stcg3000300
stcg3000300
Stcg4000300
stcg4000300

CVEs (27)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Seagate
3Stcg2000300 Firmware
Stcg3000300 FirmwareStcg4000300 Firmware
Apr 23, 2025
Dec 6, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_helper.php by leveraging...Show more
The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_helper.php by leveraging the "start" state and sending a check_device_name request.Show less
1Seagate
1Cortx S3 Server
Nov 21, 2024
Apr 7, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Denial of Service vulnerability exists in CORTX-S3 Server as of 11/7/2021 via the mempool_destroy method due to a failture to release locks pool->lock.
1Seagate
1Nas Os
Nov 21, 2024
May 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple application metadata fields: Short Description, Publisher Name, Publisher Contact, or Web...Show more
Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple application metadata fields: Short Description, Publisher Name, Publisher Contact, or Website URL.Show less
1Seagate
1Nas Os
Nov 21, 2024
May 13, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.
1Seagate
1Nas Os
Nov 21, 2024
May 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via cross-site scripting.
1Seagate
1Nas Os
Nov 21, 2024
May 13, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL of 127.0.0.1 or localhost.
1Seagate
1Nas Os
Nov 21, 2024
May 13, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'state' URL parameter.
1Seagate
1Nas Os
Nov 21, 2024
May 13, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names.
1Seagate
1Nas Os
Nov 21, 2024
May 13, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL path.
1Seagate
1Nas Os
Nov 21, 2024
May 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names.
1Seagate
1Nas Os
Nov 21, 2024
May 13, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authentication via empty POST requests.
1Seagate
1Nas Os
Nov 21, 2024
May 13, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId URL parameter.
1Seagate
1Personal Cloud Firmware
Nov 21, 2024
Apr 28, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Seagate Media Server in Seagate Personal Cloud before 4.3.18.4 has directory traversal in getPhotoPlaylistPhotos.psp via a parameter named url.
1Seagate
2Blackarmor Nas 110 Firmware
Blackarmor Nas 220 Firmware
Nov 21, 2024
Feb 23, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or the auth_name parameter to localhost/backupmgmt/pre_connect_check.php.
1Seagate
2Blackarmor Nas 110 Firmware
Blackarmor Nas 220 Firmware
Nov 21, 2024
Feb 23, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a hard-coded password of '!~@##$$%FREDESWWSED' for a backdoor user.
1Seagate
1Personal Cloud Firmware
Nov 21, 2024
Jan 12, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.py because .psp URLs are handled by the fastcgi.server component and shell metach...Show more
Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.py because .psp URLs are handled by the fastcgi.server component and shell metacharacters are mishandled.Show less
1Seagate
1St500lt015 Firmware
May 13, 2026
Nov 27, 2017
N/A· v4
4.2 MEDIUM· v3
1.9 LOW· v2
Seagate ST500LT015 hard disk drives, when operating in eDrive mode on Lenovo ThinkPad W541 laptops with BIOS 2.21, allow physically proximate attackers to bypass self-encrypting drive (SED) protection by attaching a seco...Show more
Seagate ST500LT015 hard disk drives, when operating in eDrive mode on Lenovo ThinkPad W541 laptops with BIOS 2.21, allow physically proximate attackers to bypass self-encrypting drive (SED) protection by attaching a second SATA connector to exposed pins, maintaining an alternate power source, and attaching the data cable to another machine, aka a "Hot Unplug Attack."Show less
2Samsung
Seagate
4850 Pro Firmware
Pm851 FirmwareSt500lt015 Firmware+1 more
May 13, 2026
Nov 27, 2017
N/A· v4
4.2 MEDIUM· v3
1.9 LOW· v2
Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when used on Windows and operating in Opal mode on Lenovo ThinkPad T440s laptops with BIOS 2.32 or ThinkPad W541 laptop...Show more
Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when used on Windows and operating in Opal mode on Lenovo ThinkPad T440s laptops with BIOS 2.32 or ThinkPad W541 laptops with BIOS 2.21, or in Opal or eDrive mode on Dell Latitude E6410 laptops with BIOS A16 or Latitude E6430 laptops with BIOS A16, allow physically proximate attackers to bypass self-encrypting drive (SED) protection by triggering a soft reset and booting from an alternative OS, aka a "Forced Restart Attack."Show less
2Samsung
Seagate
4850 Pro Firmware
Pm851 FirmwareSt500lt015 Firmware+1 more
May 13, 2026
Nov 27, 2017
N/A· v4
4.2 MEDIUM· v3
1.9 LOW· v2
Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when in sleep mode and operating in Opal or eDrive mode on Lenovo ThinkPad T440s laptops with BIOS 2.32; ThinkPad W541...Show more
Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when in sleep mode and operating in Opal or eDrive mode on Lenovo ThinkPad T440s laptops with BIOS 2.32; ThinkPad W541 laptops with BIOS 2.21; Dell Latitude E6410 laptops with BIOS A16; or Latitude E6430 laptops with BIOS A16, allow physically proximate attackers to bypass self-encrypting drive (SED) protection by leveraging failure to detect when SATA drives are unplugged in Sleep Mode, aka a "Hot Plug attack."Show less
1Seagate
1Blackarmor Nas 220 Firmware
May 13, 2026
Oct 11, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters in the ip parameter to backupmgt/getAlias.php.