First published: Wed Oct 11 2017(Updated: )
Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters in the ip parameter to backupmgt/getAlias.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Seagate BlackArmor NAS 220 | =sg2000-2000.1331 | |
Seagate BlackArmor NAS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6924 is classified as a high severity vulnerability due to the potential for remote command execution.
To fix CVE-2013-6924, update the Seagate BlackArmor NAS 220 firmware to the latest version provided by Seagate.
CVE-2013-6924 can be exploited via remote attacks that allow for the injection of shell metacharacters in the ip parameter.
CVE-2013-6924 specifically affects Seagate BlackArmor NAS devices running firmware version sg2000-2000.1331.
An attacker exploiting CVE-2013-6924 can execute arbitrary commands on the vulnerable Seagate BlackArmor NAS device.