First published: Thu Jun 08 2017(Updated: )
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraging use of a static encryption key to create session tokens.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Seagate Business NAS Firmware | =2014.00319 | |
Seagate Business NAS Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8687 is considered to have high severity due to the potential for remote code execution with root privileges.
To fix CVE-2014-8687, upgrade the Seagate Business NAS firmware to version 2015.00322 or later.
CVE-2014-8687 affects Seagate Business NAS devices running firmware versions prior to 2015.00322.
CVE-2014-8687 allows remote attackers to execute arbitrary code by exploiting a static encryption key used for session tokens.
CVE-2014-8687 is an unauthenticated vulnerability, allowing attackers to exploit the flaw without prior authentication.