← Back

Seagate

seagate

27 CVEs • 25 products

Products (25)

Click to collapse
Toggle
Nas Os
nas_os
Blackarmor Nas
blackarmor_nas
Business Nas
business_nas
St500lt015
st500lt015
St500lt025
st500lt025
Goflex Home
goflex_home
Stcg2000300
stcg2000300
Stcg3000300
stcg3000300
Stcg4000300
stcg4000300

CVEs (27)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Seagate
1Business Nas Firmware
May 13, 2026
Jun 8, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraging use of a static encryption key to create session tokens.
2Lacie
Seagate
5Goflex Sattelite
Lac9000436u FirmwareLac9000464u Firmware+2 more
May 6, 2026
Dec 31, 2015
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
Unrestricted file upload vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 allows remote attackers to...Show more
Unrestricted file upload vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 allows remote attackers to execute arbitrary code by uploading a file to /media/sda2 during a Wi-Fi session.Show less
2Lacie
Seagate
5Goflex Sattelite
Lac9000436u FirmwareLac9000464u Firmware+2 more
May 6, 2026
Dec 31, 2015
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Absolute path traversal vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 allows remote attackers to r...Show more
Absolute path traversal vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 allows remote attackers to read arbitrary files via a full pathname in a download request during a Wi-Fi session.Show less
2Lacie
Seagate
5Goflex Sattelite
Lac9000436u FirmwareLac9000464u Firmware+2 more
May 6, 2026
Dec 31, 2015
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 have a default password of root for the root account, which allows re...Show more
Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 have a default password of root for the root account, which allows remote attackers to obtain administrative access via a TELNET session.Show less
1Seagate
2Blackarmor Nas 220
Blackarmor Nas 220 Firmware
Apr 29, 2026
Jan 21, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple cross-site request forgery (CSRF) vulnerabilities in the Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attackers to hijack the authentication of administrators for requests that...Show more
Multiple cross-site request forgery (CSRF) vulnerabilities in the Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attackers to hijack the authentication of administrators for requests that (1) add user accounts via a crafted request to admin/access_control_user_add.php; (2) modify or (3) delete user accounts; (4) perform a factory reset; (5) perform a device reboot; or (6) add, (7) modify, or (8) delete shares and volumes.Show less
1Seagate
2Blackarmor Nas 220
Blackarmor Nas 220 Firmware
Apr 29, 2026
Jan 9, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attackers to inject arbitrary web script or HTML via the (1) fullname parameter to adm...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attackers to inject arbitrary web script or HTML via the (1) fullname parameter to admin/access_control_user_edit.php or (2) workname parameter to admin/network_workgroup_domain.php.Show less
1Seagate
1Blackarmor Nas
Apr 29, 2026
May 25, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
d41d8cd98f00b204e9800998ecf8427e.php in the management web server on the Seagate BlackArmor device allows remote attackers to change the administrator password via unspecified vectors.