CVE-2015-2874: Critical severity seagate wireless plus mobile storage vulnerability
Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 have a default password of root for the root account, which allows remote attackers to obtain administrative access via a TELNET session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2874?
CVE-2015-2874 is considered a high severity vulnerability due to the presence of a default password for the root account, allowing unauthorized access.
How do I fix CVE-2015-2874?
To mitigate CVE-2015-2874, update the firmware of affected devices to version 3.4.1.105 or later, which removes the default password.
What devices are affected by CVE-2015-2874?
CVE-2015-2874 affects Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, and Seagate Wireless Plus Mobile Storage devices with firmware prior to 3.4.1.105.
Can CVE-2015-2874 be exploited remotely?
Yes, CVE-2015-2874 can be exploited remotely by attackers through a TELNET session due to the default root password.
Is there a workaround for CVE-2015-2874?
The primary workaround for CVE-2015-2874 is to change the default root password on affected devices, though updating the firmware is recommended for complete security.