CVE-2014-8687: Critical severity seagate business nas firmware vulnerability
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraging use of a static encryption key to create session tokens.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8687?
CVE-2014-8687 is considered to have high severity due to the potential for remote code execution with root privileges.
How do I fix CVE-2014-8687?
To fix CVE-2014-8687, upgrade the Seagate Business NAS firmware to version 2015.00322 or later.
Which devices are affected by CVE-2014-8687?
CVE-2014-8687 affects Seagate Business NAS devices running firmware versions prior to 2015.00322.
What type of attack is possible with CVE-2014-8687?
CVE-2014-8687 allows remote attackers to execute arbitrary code by exploiting a static encryption key used for session tokens.
Is CVE-2014-8687 an authenticated or unauthenticated vulnerability?
CVE-2014-8687 is an unauthenticated vulnerability, allowing attackers to exploit the flaw without prior authentication.