CVE-2013-6924: Command Injection
Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters in the ip parameter to backupmgt/getAlias.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6924?
CVE-2013-6924 is classified as a high severity vulnerability due to the potential for remote command execution.
How do I fix CVE-2013-6924?
To fix CVE-2013-6924, update the Seagate BlackArmor NAS 220 firmware to the latest version provided by Seagate.
What types of attacks can exploit CVE-2013-6924?
CVE-2013-6924 can be exploited via remote attacks that allow for the injection of shell metacharacters in the ip parameter.
Which devices are affected by CVE-2013-6924?
CVE-2013-6924 specifically affects Seagate BlackArmor NAS devices running firmware version sg2000-2000.1331.
What can an attacker do with CVE-2013-6924?
An attacker exploiting CVE-2013-6924 can execute arbitrary commands on the vulnerable Seagate BlackArmor NAS device.